Skip to main content

Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

In general, Kafka has a 1-year support window, so currently we are supporting 4.3, 4.2, and 4.1 release: https://kafka.apache.org/community/downloads/#supported-releases With the upcoming 4.4.0 release, 4.1 will drop out of the support window. So it's very unlikely that we would ship another 3.9.x bug-fix release. Given that 3.9 is the last release with ZK support, and upgrading to 4.x requires to migrate to KRaft, there is a possibility that we might maintain 3.9.x for a little longer than usual. However, officially 3.9 is not supported any longer, and the 3.9 and 4.0 release got archived already: https://kafka.apache.org/community/downloads/#archived-releases -Matthias On 8/19/26 7:21 AM, Gergely Harmadás wrote: > Hi James, > > I am not a project maintainer, just an enthusiastic contributor who > happened to have the same problem with lz4 :) There are some discussion > about a possible 3.9 release in this thread, so far no concrete plans > https://lists.apache.org/thread/bq27on99lf5b24d16zt5g5hnysd30c3w > > Best regards, > Gergely > > On Mon, 17 Aug 2026 at 13:54, JAMES JOSE <jamejose@in.ibm.com> wrote: > >> Hello Gergely, >> >> Any plan for patching 3.9.* release with fixed version of lz4-java ? >> >> Regards, >> James >> >> -----Original Message----- >> From: JAMES JOSE >> Sent: 17 August 2026 16:10 >> To: 'users@kafka.apache.org' <users@kafka.apache.org> >> Subject: RE: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) >> >> Thanks for the information. >> >> Regards, >> James >> >> -----Original Message----- >> From: Gergely Harmadás <harmadasg@gmail.com> >> Sent: 14 August 2026 16:58 >> To: users@kafka.apache.org >> Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java) >> >> Hi James, >> >> The update to 1.11.1 was covered in KAFKA-20842 < >> https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e= >>> . The CVE fix will be included in the upcoming Kafka 4.4 release which is >> targeted for September according to the Release Plan < >> https://urldefense.proofpoint.com/v2/url?u=https-3A__cwiki.apache.org_confluence_spaces_KAFKA_pages_429064575_Release-2BPlan-2B4.4.0&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=sf7VZBPkv6KzQsEateGr841NKrq0epSCQO05WlzYBOA&e= >>> . >> There was also a backport to the 4.3 branch which means the CVE fix will >> be included in a subsequent release, but AFAIK there is no planned date yet >> for 4.3.2. >> >> As a side-note I have noticed there is new security release for lz4, >> created KAFKA-20937 < >> https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20937&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=1rC8kX7_JaOzD_UXptNGM7VeglnyMjTuXu0WympUDaU&e= >>> to track the update. >> >> Best regards, >> Gergely >> >> On Thu, 13 Aug 2026 at 05:59, JAMES JOSE <jamejose@in.ibm.com> wrote: >> >>> Hi Team, >>> >>> As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), >>> lz4-java versions up to and including 1.11.0 are affected, with the >>> issue fixed in version 1.11.1. GitHub Advisory – GHSA-xx22-p4ch-683r< >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_adviso >>> ries_GHSA-2Dxx22-2Dp4ch-2D683r-3Futm-5Fsource-3Dchatgpt.com&d=DwIFaQ&c >>> =BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs& >>> m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=0 >>> leyUvEfu72D5H17gecX__uM3pEjIrAPlZfVtSbZ0CI&e= > >>> >>> We understand that the latest Kafka version currently uses >> lz4-java-1.10.2. >>> >>> Could you please confirm whether this means Kafka is affected by >>> CVE-2026-59949 and whether Kafka needs to be updated to use lz4-java >>> 1.11.1 or later? >>> >>> If a Kafka update is required, could you also let us know whether >>> there is a planned Kafka release that will include the fixed version, >>> and the expected release date? >>> >>> Thanks, >>> James >>> >>> >> >

Comments