Skip to main content

Posts

Re: Kafka v4.3.0 Jackson related vulnerabilities

Hello Luke and Vivek, I have gone ahead and created KAFKA-21004 <https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix (also opened a PR) Regards, Gergely On Mon, 31 Aug 2026 at 11:10, Luke Chen <showuon@gmail.com> wrote: > Hi Vivek, > > Thanks for reporting this issue. > Could you please open a JIRA > <http://issues.apache.org/jira/browse/KAFKA> ticket > for this issue? > And if possible, welcome to create a PR for it. > > From the current schedule, it should be included in v4.5.0. > > Thanks, > Luke > > On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < > users@kafka.apache.org> wrote: > > > Hi, > > > > In our product, kafka v4.3.0 is used. Below Jackson related > vulnerability > > is reported on this kafka version - > > > > CVE-2026-68497 > > This vulnerability is fixed in jackson databind v2.21.6. I se...

Re: Kafka v4.3.0 Jackson related vulnerabilities

Hi Vivek, Thanks for reporting this issue. Could you please open a JIRA <http://issues.apache.org/jira/browse/KAFKA> ticket for this issue? And if possible, welcome to create a PR for it. From the current schedule, it should be included in v4.5.0. Thanks, Luke On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < users@kafka.apache.org> wrote: > Hi, > > In our product, kafka v4.3.0 is used. Below Jackson related vulnerability > is reported on this kafka version - > > CVE-2026-68497 > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming > release kafka v4.4.0 bumped Jackson bind version to v2.21.5 > Please confirm which apache kafka upcoming versions will upgrade to > Jackson bind v2.21.6 > > Regards > Vivek > >

Kafka v4.3.0 Jackson related vulnerabilities

Hi, In our product, kafka v4.3.0 is used. Below Jackson related vulnerability is reported on this kafka version - CVE-2026-68497 This vulnerability is fixed in jackson databind v2.21.6. I see upcoming release kafka v4.4.0 bumped Jackson bind version to v2.21.5 Please confirm which apache kafka upcoming versions will upgrade to Jackson bind v2.21.6 Regards Vivek

setting up log4j2 for Kafka Provider

Good Afternoon, Am looking to control log4j2 output produced by Kafka...but am having a little difficultly getting this to work as expected. During the kafka producer startup I've added this command: -Dlog4j2.configurationFile=/<whatever>/kafka/producers/log4j2.properties I've created a log4j2.properties file as follows: # Root Logger rootLogger=INFO, STDERR # Direct log messages to stderr appender.console.type = Console appender.console.name = STDERR appender.console.layout.type = PatternLayout appender.console.layout.pattern = [%-5level] %d{yyyy-MM-dd HH:mm:ss.SSS} [%t] %C{1} - %msg%n Yet, when I look at STDERR am not seeing the desired messages. Do I need to configure slf4j instead or in conjunction? Anything I'm possibly doing wrong? Anyone with experience on customizing kafka message logging, will to chime in? Thank You, --Alex

Re: Kafka Streams Abnormal Latency & Lag Spiking Under High Load

Not sure if this is at all helpful, but we also experienced poor performance with Kafka Streams, and it took us quite a while to figure out all the tuning knobs, but we found that in our case we were experiencing extended RocksDB write stalls (overfilling memtables causing RocksDB to stall and eventually pause writes) which led to extended commit periods which led to large application latency gaps... I am not at all sure if you hit the same problem, but I would recommend enabling as many debug metrics as you can handle, turn on RocksDB stats logging, and in our case we ran a Claude Code instance with access to logs, dashboards, JFR dump (incl stack sampling) and it was actually quite good at identifying problematic configuration. You can't trust everything it says, but it can highlight things you didn't even consider... > On Aug 8, 2026, at 6:52 PM, Brebner, Paul via users <users@kafka.apache.org> wrote: > > Hi Tamar, > > Interesting problem...

Re: [ANNOUNCE] New committer: Jiunn-Yang Huang

Congrats! On 8/24/26 12:26 PM, o.g.h.ibrahim@gmail.com wrote: > Congratulations! > > Omnia > Sent from my iPhone > >> On 24 Aug 2026, at 08:27, Sanghyeok An <ojt90902@gmail.com> wrote: >> >> Congratulations! Well-deserved! >> >> Regards, >> Sanghyeok An >> >> 2026년 8월 24일 (월) 오후 4:15, Muralidhar Basani via dev <dev@kafka.apache.org>님이 >> 작성: >> >>> Congratulations! >>> >>> Regards, >>> Murali >>> >>>> On Mon, Aug 24, 2026 at 2:55 AM Luke Chen <showuon@gmail.com> wrote: >>>> >>>> Congratulations! Well deserved! >>>> Please remember to help review PRs and KIPs. :) >>>> >>>> Luke >>>> >>>>> On Mon, Aug 24, 2026 at 9:35 AM jian fu <fujian1115@gmail.com> wrote: >>>> >>>>> Congratulations! ...

Re: Kafka v4.3.0 JLine related vulnerabilities

Hi Vivek, The CVE was fixed in the scope of KAFKA-20815 <https://issues.apache.org/jira/browse/KAFKA-20815> and will be included in the upcoming 4.4 release. You can find my analysis about the CVE in this <https://issues.apache.org/jira/browse/KAFKA-20815?focusedCommentId=18097890&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-18097890> comment. Best regards, Gergely On Fri, 21 Aug 2026 at 08:22, Vivek Agarwal B via users < users@kafka.apache.org> wrote: > Hello Apache Kafka Team, > > In our product, kafka v4.3.0 is used. Below 2 Jline related > vulnerabilities are reported on this kafka version - > > CVE-2026-56740 > CVE-2026-56741 > > I see in kafka v4.3.0, jline-3.30.4.jar is present in the libs folder - > libs/jline-3.30.4.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml. > > As per github advisory, these vulnerabilities are fixed in Jline v4.2.1 > ver...