Hello Apache Kafka Team,
In our product, kafka v4.3.0 is used. Below 2 Jline related vulnerabilities are reported on this kafka version -
CVE-2026-56740
CVE-2026-56741
I see in kafka v4.3.0, jline-3.30.4.jar is present in the libs folder - libs/jline-3.30.4.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml.
As per github advisory, these vulnerabilities are fixed in Jline v4.2.1 versions.
[1] CVE-2026-56740 Official Advisory - https://github.com/advisories/GHSA-47qp-hqvx-6r3f
[2] CVE-2026-56741 Official Advisory - https://github.com/advisories/GHSA-2r2c-cx56-8933
Please confirm what apache kafka upcoming versions will upgrade to Jline v.4.2.1.
Regards
Vivek