Description
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.
Published: 2026-06-02
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Klaw arises from inconsistent handling of username case sensitivity during registration and login. This flaw permits an attacker to trigger a targeted denial of service by locking a user’s account permanently. The resulting impact is limited to the affected account’s availability; it does not expose data or elevate privileges. The flaw is associated with CWE‑178 and CWE‑20.

Affected Systems

The issue affects the Aiven‑Open Klaw application, a self‑service Apache Kafka topic management portal. All releases prior to version 2.10.4 of Klaw are vulnerable. No other vendors or products are listed in the CNA data.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity. EPSS is not available, so the precise likelihood of exploitation cannot be quantified, but the flaw can be exercised by any actor who can access the login interface. The vulnerability is not listed in CISA’s KEV catalog, and no additional exploitation prerequisites are described, suggesting that an attacker can trigger the DoS simply by sending requests that exploit the case‑sensitivity mismatch. The patch released in 2.10.4 removes the inconsistency and resolves the lockout behavior.

Generated by OpenCVE AI on June 2, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Klaw to version 2.10.4 or later.
  • Re‑enable or recreate any user accounts that were locked during the attack before deploying the new version.
  • Perform an audit of user activity to confirm that no accounts remain locked and that login functionality is operating with consistent case sensitivity.

Generated by OpenCVE AI on June 2, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Aiven-open
Aiven-open klaw
Vendors & Products Aiven-open
Aiven-open klaw

Tue, 02 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.
Title Klaw: user lockout due to case sensitivity inconsistency
Weaknesses CWE-178
CWE-20
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-02T15:55:58.686Z

Reserved: 2026-05-05T20:15:20.631Z

Link: CVE-2026-44367

cve-icon Vulnrichment

Updated: 2026-06-02T15:55:55.507Z

cve-icon NVD

Status : Deferred

Published: 2026-06-02T16:16:41.043

Modified: 2026-06-02T17:15:44.040

Link: CVE-2026-44367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T16:30:13Z

Weaknesses