Skip to main content

Posts

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

In general, Kafka has a 1-year support window, so currently we are supporting 4.3, 4.2, and 4.1 release: https://kafka.apache.org/community/downloads/#supported-releases With the upcoming 4.4.0 release, 4.1 will drop out of the support window. So it's very unlikely that we would ship another 3.9.x bug-fix release. Given that 3.9 is the last release with ZK support, and upgrading to 4.x requires to migrate to KRaft, there is a possibility that we might maintain 3.9.x for a little longer than usual. However, officially 3.9 is not supported any longer, and the 3.9 and 4.0 release got archived already: https://kafka.apache.org/community/downloads/#archived-releases -Matthias On 8/19/26 7:21 AM, Gergely Harmadás wrote: > Hi James, > > I am not a project maintainer, just an enthusiastic contributor who > happened to have the same problem with lz4 :) There are some discussion > about a possible 3.9 release in this thread, so far no concrete...

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James, I am not a project maintainer, just an enthusiastic contributor who happened to have the same problem with lz4 :) There are some discussion about a possible 3.9 release in this thread, so far no concrete plans https://lists.apache.org/thread/bq27on99lf5b24d16zt5g5hnysd30c3w Best regards, Gergely On Mon, 17 Aug 2026 at 13:54, JAMES JOSE <jamejose@in.ibm.com> wrote: > Hello Gergely, > > Any plan for patching 3.9.* release with fixed version of lz4-java ? > > Regards, > James > > -----Original Message----- > From: JAMES JOSE > Sent: 17 August 2026 16:10 > To: 'users@kafka.apache.org' <users@kafka.apache.org> > Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) > > Thanks for the information. > > Regards, > James > > -----Original Message----- > From: Gergely Harmadás <harmadasg@gmail.com> > Sent: 14 August 2026 16:58 > To: users@k...

Monotonic LogAppendTime when leader changes

Hi, we have recently observed an increased amount of decreasing logappendtime events when the leader changed. It would be very helpful, if the logappendtime would never decrease for our use case. It seems possible to fix this with a minimal change by tracking the lastLogAppendTimeMs in the UnifiedLog.java and then force the now timestamp to be clamped with this lower bound. Is this something that we could contribute? thanks Alexander

RE: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hello Gergely, Any plan for patching 3.9.* release with fixed version of lz4-java ? Regards, James -----Original Message----- From: JAMES JOSE Sent: 17 August 2026 16:10 To: 'users@kafka.apache.org' <users@kafka.apache.org> Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Thanks for the information. Regards, James -----Original Message----- From: Gergely Harmadás <harmadasg@gmail.com> Sent: 14 August 2026 16:58 To: users@kafka.apache.org Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e= >. The CVE fix will be includ...

RE: CVE-2026-59949 – Impact on Kafka (lz4-java)

Thanks for the information. Regards, James -----Original Message----- From: Gergely Harmadás <harmadasg@gmail.com> Sent: 14 August 2026 16:58 To: users@kafka.apache.org Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e= >. The CVE fix will be included in the upcoming Kafka 4.4 release which is targeted for September according to the Release Plan <https://urldefense.proofpoint.com/v2/url?u=https-3A__cwiki.apache.org_confluence_spaces_KAFKA_pages_429064575_Release-2BPlan-2B4.4.0&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs...

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://issues.apache.org/jira/browse/KAFKA-20842>. The CVE fix will be included in the upcoming Kafka 4.4 release which is targeted for September according to the Release Plan <https://cwiki.apache.org/confluence/spaces/KAFKA/pages/429064575/Release+Plan+4.4.0>. There was also a backport to the 4.3 branch which means the CVE fix will be included in a subsequent release, but AFAIK there is no planned date yet for 4.3.2. As a side-note I have noticed there is new security release for lz4, created KAFKA-20937 <https://issues.apache.org/jira/browse/KAFKA-20937> to track the update. Best regards, Gergely On Thu, 13 Aug 2026 at 05:59, JAMES JOSE <jamejose@in.ibm.com> wrote: > Hi Team, > > As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), > lz4-java versions up to and including 1.11.0 are affected, with the issue > fixed in version 1.11.1. GitHub A...

CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi Team, As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), lz4-java versions up to and including 1.11.0 are affected, with the issue fixed in version 1.11.1. GitHub Advisory – GHSA-xx22-p4ch-683r<https://github.com/advisories/GHSA-xx22-p4ch-683r?utm_source=chatgpt.com> We understand that the latest Kafka version currently uses lz4-java-1.10.2. Could you please confirm whether this means Kafka is affected by CVE-2026-59949 and whether Kafka needs to be updated to use lz4-java 1.11.1 or later? If a Kafka update is required, could you also let us know whether there is a planned Kafka release that will include the fixed version, and the expected release date? Thanks, James