CVE-2026-44575

Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update

Description

A flaw was found in Next.js. App Router applications that use middleware or proxy-based authorization checks are vulnerable to unauthorized access. A remote attacker can exploit this by crafting specific .rsc and segment-prefetch URLs, which bypass the intended middleware rules. This allows access to protected content without proper authorization.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
74.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.6 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-12 19:35 UTC
CWE-288

Weakness classes (CWE)

  • CWE-288Base

    Authentication Bypass Using an Alternate Path or Channel

    The product requires authentication, but the product has an alternate path or channel that does not require authentication.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-31 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Streams for Apache Kafka 2.9.4, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.4 (+13)Streams for Apache Kafka 2.9.4, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.4 (+12)
  2. CVE Modified2026-07-30 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Streams for Apache Kafka 2.9.4, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.4 (+12)Streams for Apache Kafka 2.9.4, Red Hat Trusted Artifact Signer 1.3, Red Hat Trusted Artifact Signer 1.4 (+13)
  3. CVE Modified2026-07-03 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:34608
    • Affected: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Trusted Artifact Signer, streams for Apache Kafka 2 (+5)Streams for Apache Kafka 2.9.4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Trusted Artifact Signer (+5)

Affected operating systems

  • linux

    ubuntu / nettynoble

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    kafka2.8.0 – 3.9.2

  • apache

    kafka4.0.0 – 4.0.2

  • apache

    kafka4.1.0 – 4.1.2

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • eclipse

    vert.x4.0.0 – 4.5.29

  • eclipse

    vert.x5.0.0 – 5.1.4

  • go

    stdlib1.26.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    go1.25.9

  • golang

    net0.55.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

References & sources

Linked CVEs

Show 33 more CVEs
IDCVE-2026-44575