CVE-2026-57915: Apache Software Foundation Apache Kerby
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Affected products
- Apache Software Foundation Apache Kerby: before 2.1.2 (fixed in 2.1.2)
- Red Hat Red Hat Amq Clients
- Red Hat Red Hat Data Grid 8
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Streams For Apache Kafka 2
- Red Hat Streams For Apache Kafka 3
Published 2026-06-26. Last modified 2026-08-03.