Skip to main content

Posts

Kafka v4.3.0 JLine related vulnerabilities

Hello Apache Kafka Team, In our product, kafka v4.3.0 is used. Below 2 Jline related vulnerabilities are reported on this kafka version - CVE-2026-56740 CVE-2026-56741 I see in kafka v4.3.0, jline-3.30.4.jar is present in the libs folder - libs/jline-3.30.4.jar/META-INF/maven/org.jline/jline-remote-telnet/pom.xml. As per github advisory, these vulnerabilities are fixed in Jline v4.2.1 versions. [1] CVE-2026-56740 Official Advisory - https://github.com/advisories/GHSA-47qp-hqvx-6r3f [2] CVE-2026-56741 Official Advisory - https://github.com/advisories/GHSA-2r2c-cx56-8933 Please confirm what apache kafka upcoming versions will upgrade to Jline v.4.2.1. Regards Vivek

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

In general, Kafka has a 1-year support window, so currently we are supporting 4.3, 4.2, and 4.1 release: https://kafka.apache.org/community/downloads/#supported-releases With the upcoming 4.4.0 release, 4.1 will drop out of the support window. So it's very unlikely that we would ship another 3.9.x bug-fix release. Given that 3.9 is the last release with ZK support, and upgrading to 4.x requires to migrate to KRaft, there is a possibility that we might maintain 3.9.x for a little longer than usual. However, officially 3.9 is not supported any longer, and the 3.9 and 4.0 release got archived already: https://kafka.apache.org/community/downloads/#archived-releases -Matthias On 8/19/26 7:21 AM, Gergely Harmadás wrote: > Hi James, > > I am not a project maintainer, just an enthusiastic contributor who > happened to have the same problem with lz4 :) There are some discussion > about a possible 3.9 release in this thread, so far no concrete...

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James, I am not a project maintainer, just an enthusiastic contributor who happened to have the same problem with lz4 :) There are some discussion about a possible 3.9 release in this thread, so far no concrete plans https://lists.apache.org/thread/bq27on99lf5b24d16zt5g5hnysd30c3w Best regards, Gergely On Mon, 17 Aug 2026 at 13:54, JAMES JOSE <jamejose@in.ibm.com> wrote: > Hello Gergely, > > Any plan for patching 3.9.* release with fixed version of lz4-java ? > > Regards, > James > > -----Original Message----- > From: JAMES JOSE > Sent: 17 August 2026 16:10 > To: 'users@kafka.apache.org' <users@kafka.apache.org> > Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) > > Thanks for the information. > > Regards, > James > > -----Original Message----- > From: Gergely Harmadás <harmadasg@gmail.com> > Sent: 14 August 2026 16:58 > To: users@k...

Monotonic LogAppendTime when leader changes

Hi, we have recently observed an increased amount of decreasing logappendtime events when the leader changed. It would be very helpful, if the logappendtime would never decrease for our use case. It seems possible to fix this with a minimal change by tracking the lastLogAppendTimeMs in the UnifiedLog.java and then force the now timestamp to be clamped with this lower bound. Is this something that we could contribute? thanks Alexander

RE: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hello Gergely, Any plan for patching 3.9.* release with fixed version of lz4-java ? Regards, James -----Original Message----- From: JAMES JOSE Sent: 17 August 2026 16:10 To: 'users@kafka.apache.org' <users@kafka.apache.org> Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Thanks for the information. Regards, James -----Original Message----- From: Gergely Harmadás <harmadasg@gmail.com> Sent: 14 August 2026 16:58 To: users@kafka.apache.org Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e= >. The CVE fix will be includ...

RE: CVE-2026-59949 – Impact on Kafka (lz4-java)

Thanks for the information. Regards, James -----Original Message----- From: Gergely Harmadás <harmadasg@gmail.com> Sent: 14 August 2026 16:58 To: users@kafka.apache.org Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e= >. The CVE fix will be included in the upcoming Kafka 4.4 release which is targeted for September according to the Release Plan <https://urldefense.proofpoint.com/v2/url?u=https-3A__cwiki.apache.org_confluence_spaces_KAFKA_pages_429064575_Release-2BPlan-2B4.4.0&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs...

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James, The update to 1.11.1 was covered in KAFKA-20842 <https://issues.apache.org/jira/browse/KAFKA-20842>. The CVE fix will be included in the upcoming Kafka 4.4 release which is targeted for September according to the Release Plan <https://cwiki.apache.org/confluence/spaces/KAFKA/pages/429064575/Release+Plan+4.4.0>. There was also a backport to the 4.3 branch which means the CVE fix will be included in a subsequent release, but AFAIK there is no planned date yet for 4.3.2. As a side-note I have noticed there is new security release for lz4, created KAFKA-20937 <https://issues.apache.org/jira/browse/KAFKA-20937> to track the update. Best regards, Gergely On Thu, 13 Aug 2026 at 05:59, JAMES JOSE <jamejose@in.ibm.com> wrote: > Hi Team, > > As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), > lz4-java versions up to and including 1.11.0 are affected, with the issue > fixed in version 1.11.1. GitHub A...