Impact
Splunk Connect for Kafka before version 2.2.7 evaluates user‑supplied regular expressions within the timestamp extraction feature without imposing a time limit. An unauthenticated attacker who can reach the Kafka Connect REST API may submit a specially crafted expression and matching event data, causing the worker thread to become stuck in a regular‑expression evaluation loop. The result is a denial of service that halts event delivery for the affected connector, disrupting the availability of the data pipeline.
Affected Systems
Products affected are Splunk Connect for Kafka, versions earlier than 2.2.7. The flaw is exposed through the REST API that is accessible to any user with network reachability to the Kafka Connect cluster. No other Splunk products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as medium severity. Because the attack vector is unauthenticated HTTP access to the REST API, the risk is limited to environments where the API is exposed to untrusted networks. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, which reduces the likelihood of widespread exploitation. Nevertheless, the impact is significant for services that rely on continuous data ingestion.
OpenCVE Enrichment