Hi Team,
As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), lz4-java versions up to and including 1.11.0 are affected, with the issue fixed in version 1.11.1. GitHub Advisory – GHSA-xx22-p4ch-683r<https://github.com/advisories/GHSA-xx22-p4ch-683r?utm_source=chatgpt.com>
We understand that the latest Kafka version currently uses lz4-java-1.10.2.
Could you please confirm whether this means Kafka is affected by CVE-2026-59949 and whether Kafka needs to be updated to use lz4-java 1.11.1 or later?
If a Kafka update is required, could you also let us know whether there is a planned Kafka release that will include the fixed version, and the expected release date?
Thanks,
James