Hi Omnia,
Several vulnerabilities have been identified in the libraries included in the Kafka 4.4.0 release candidate (RC). Considering the number and severity of these vulnerabilities, could you please consider upgrading the affected libraries to the specified fixed versions as part of Kafka 4.4.0 itself?
Upgrading these dependencies before the final Kafka 4.4.0 release would help address the identified security findings and avoid additional remediation activities after release.
The details are provided below:
1. Jetty
Current version: 12.0.37
Recommended version: 12.0.39
Vulnerabilities addressed:
CVE-2026-12611
CVE-2026-19203
CVE-2026-19204
2. Jackson
Current version: 2.21.6
Recommended version: 2.21.7
Vulnerabilities addressed:
CVE-2026-91776
CVE-2026-91777
CVE-2026-89425
CVE-2026-89407
3. zstd-jni
Current version: 1.5.6-10
Recommended version: 1.5.7-20
Vulnerabilities addressed:
CVE-2026-87795
CVE-2026-87825
CVE-2026-90560
CVE-2026-87824
CVE-...