A vulnerability was found in Apache Kafka Clients up to 3.9.1/4.0.1/4.1.1 and classified as critical. This issue affects some unknown processing of the component Producer Message Handler. Executing a manipulation can lead to use after free.

The identification of this vulnerability is CVE-2026-35554. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.