Hi, As per below mentioned ticket, CVE-2026-68497 fix will be included in kafka v4.4.0<https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0> Is my understanding correct? Thanks Ashish Verma From: Gergely Harmadás <harmadasg@gmail.com> Sent: 31 August 2026 21:56 To: users@kafka.apache.org Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Vivek Agarwal B <vivek.b.agarwal@ericsson.com> Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities Hello Luke and Vivek, I have gone ahead and created KAFKA-21004<https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix (also opened a PR) Regards, Gergely On Mon, 31 Aug 2026 at 11:10, Luke Chen <showuon@gmail.com<mailto:showuon@gmail.com>> wrote: Hi Vivek, Thanks for reporting this issue. Could you please open a JIRA <http://issues.apache.org/jira/browse/KAFKA> ticket for this issue? And if possible, welcome to create a PR for it. From the current schedule, it should be included in v4.5.0. Thanks, Luke On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < users@kafka.apache.org<mailto:users@kafka.apache.org>> wrote: > Hi, > > In our product, kafka v4.3.0 is used. Below Jackson related vulnerability > is reported on this kafka version - > > CVE-2026-68497 > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming > release kafka v4.4.0 bumped Jackson bind version to v2.21.5 > Please confirm which apache kafka upcoming versions will upgrade to > Jackson bind v2.21.6 > > Regards > Vivek > >
Comments
Post a Comment