Impact
Splunk Connect for Kafka versions older than 2.2.7 enable an unauthenticated attacker who can reach the Kafka Connect REST API to trigger continuous retries of failed event batches sent to the HTTP Event Collector. The retry logic uses an unbounded default, causing the connector to consume resources until event delivery ceases, effectively denying access to Splunk for legitimate data ingestion. This is an uncontrolled resource consumption flaw (CWE-400) that impairs availability.
Affected Systems
Splunk Connect for Kafka deployments running any version prior to 2.2.7 are affected. The vulnerability applies to the component that exposes the Kafka Connect REST API and forwards data to the Splunk HTTP Event Collector endpoint.
Risk and Exploitability
The CVSS score of 5.9 classifies the issue as medium severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers need network access to the Kafka Connect REST API and do not require authentication, making the attack vector simple but limited to systems that expose the API over the network. Once accessed, the attacker can trigger resource exhaustion and interrupt data ingestion.
OpenCVE Enrichment