DescriptionConfluent Kafka Python through 2.14.2 contains a disabled TLS certificate verification vulnerability that allows a network man-in-the-middle attacker to impersonate the HashiCorp Vault server by exploiting the hardcoded verify=False setting in the hvac.Client used for Schema Registry field-encryption rules via hcvault:// key URIs. Attackers can intercept HTTPS connections to present attacker-controlled or self-signed certificates to capture Vault authentication material such as X-Vault-Token or AppRole credentials and return forged KMS responses, compromising the confidentiality and integrity of Vault-backed encrypted data.