Description
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Data ingestion parameters for Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/overview/data-ingestion-parameters-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.
Published: 2026-08-19
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk Connect for Kafka versions older than 2.2.7 enable an unauthenticated attacker who can reach the Kafka Connect REST API to trigger continuous retries of failed event batches sent to the HTTP Event Collector. The retry logic uses an unbounded default, causing the connector to consume resources until event delivery ceases, effectively denying access to Splunk for legitimate data ingestion. This is an uncontrolled resource consumption flaw (CWE-400) that impairs availability.

Affected Systems

Splunk Connect for Kafka deployments running any version prior to 2.2.7 are affected. The vulnerability applies to the component that exposes the Kafka Connect REST API and forwards data to the Splunk HTTP Event Collector endpoint.

Risk and Exploitability

The CVSS score of 5.9 classifies the issue as medium severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers need network access to the Kafka Connect REST API and do not require authentication, making the attack vector simple but limited to systems that expose the API over the network. Once accessed, the attacker can trigger resource exhaustion and interrupt data ingestion.

Generated by OpenCVE AI on August 20, 2026 at 10:34 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Restrict access to the Kafka Connect Representational State Transfer (REST) API to trusted administrative hosts and networks. Set a finite HTTP Event Collector retry limit in the connector configuration. For more information see [Data ingestion parameters for Splunk Connect for Kafka](https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/overview/data-ingestion-parameters-for-splunk-connect-for-kafka) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Connect for Kafka to version 2.2.7 or later.
  • Restrict network access to the Kafka Connect REST API to trusted administrative hosts or networks.
  • Configure a finite HTTP Event Collector retry limit in the connector’s configuration file, following the guidelines in Splunk’s documentation.

Generated by OpenCVE AI on August 20, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk connect For Kafka
CPEs cpe:2.3:a:splunk:connect_for_kafka:*:*:*:*:*:*:*:*
Vendors & Products Splunk connect For Kafka

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Connect For Kafka
Vendors & Products Splunk
Splunk splunk Connect For Kafka

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Data ingestion parameters for Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/overview/data-ingestion-parameters-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.
Title Denial of Service (DoS) through the REST API in Splunk Connect for Kafka
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Splunk Connect For Kafka Splunk Connect For Kafka
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:31.906Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76400

cve-icon Vulnrichment

Updated: 2026-08-20T15:24:19.793Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:26.647

Modified: 2026-08-24T19:03:38.300

Link: CVE-2026-76400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption