CVE-2025-27818 | Apache Kafka up to 3.9.0 SASL JAAS LdapLoginModule deserialization (EUVD-2025-17639)
A vulnerability has been found in Apache Kafka up to 3.9.0 and classified as critical. This vulnerability affects unknown code of the component SASL JAAS LdapLoginModule Handler. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-27818. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.