Public CVE Reference
CVE-2026-15911
Impacted versions
- confluent-kafka (Python) <= 2.14.2, when used with:
- Schema Registry client-side field-level encryption (CSFLE) rules; and
- The HashiCorp Vault KMS provider (key URIs using the hcvault:// scheme) reached over HTTPS.
- Confluent Platform: not impacted (see Remediation).
- Confluent Cloud: not impacted (see Remediation).
Recommended action
- Upgrade the confluent-kafka Python package to 2.15.0 or later in any application that uses the HashiCorp Vault CSFLE integration.
- After upgrading, configure ssl.ca.location or VAULT_CACERT if your Vault server presents a certificate signed by a private or internal certificate authority.
Issue
A security vulnerability has been identified in the Confluent Kafka Python client's HashiCorp Vault KMS integration, used for Schema Registry client-side field-level encryption (CSFLE). The client's underlying HTTP connection to Vault had TLS certificate verification hardcoded to disabled, with no configuration option exposed to re-enable it.
A network-positioned attacker able to intercept traffic between the application and its Vault server could impersonate the server with any certificate, including a self-signed one, and thereby capture the Vault access token and AppRole credentials in transit, or return manipulated responses affecting KMS key wrap/unwrap operations. Exploitation requires no application-level authentication but does require a privileged network position between the client and Vault.
This issue is specific to the HashiCorp Vault KMS client; the AWS, Google Cloud, and Azure KMS clients in the same package verify certificates by default and are not affected.
Remediation
-
confluent-kafka (Python): This issue has been addressed in confluent-kafka (Python) 2.15.0, which:
- Enables TLS certificate verification by default.
- Exposes configuration to supply a custom CA bundle and an optional client certificate for mutual TLS, through both driver configuration and standard Vault environment variables:
- ssl.ca.location (or environment variable VAULT_CACERT): CA bundle used to verify the Vault server certificate.
- ssl.certificate.location (or environment variable VAULT_CLIENT_CERT): client certificate for mutual TLS.
- ssl.key.location (or environment variable VAULT_CLIENT_KEY): client private key for mutual TLS.
- An empty or unset CA value keeps verification enabled; it does not silently disable verification.
- Confluent Platform: Not affected. The vulnerability resides in the confluent-kafka Python client library and does not affect Confluent Platform server components or their released versions.
- Confluent Cloud: Not affected. No remediation is required for Confluent Cloud.
CVSS Scores
- CVSS v3.1 base score: 7.4 High (CVSS v3.1 Calculator)
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Acknowledgements
Rahul Karne is credited for responsibly reporting this issue via VulnCheck.