Skip to main content

Posts

Re: Kafka 4.4.0 formal release date -- Important

No updates... We are waiting for RC2. But today, a potentially new blocker bug was found... On 9/16/26 4:35 AM, Vivek Agarwal B wrote: > Hi Matthias, > > Do we now have a confirmed date for the formal release of Kafka 4.4.0? > > Regards > Vivek > > -----Original Message----- > From: Matthias J. Sax <mjsax@apache.org> > Sent: 10 September 2026 02:49 > To: users@kafka.apache.org; Vivek Agarwal B <vivek.b.agarwal@ericsson.com> > Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Mayank Maheshwari M <mayank.m.maheshwari@ericsson.com> > Subject: Re: Kafka 4.4.0 formal release date -- Important > > [You don't often get email from mjsax@apache.org. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] > > As an open source project, we don't have committed release dates. The page literally says "no earlier than": > > > meaning we expect ...

Re: Kafka 4.4.0 formal release date -- Important

No updates... We are waiting for RC2. But today, a potentially new blocker bug was found... On 9/16/26 5:27 AM, Mayank Maheshwari M wrote: > Hi @Matthias J. Sax, > > Unfortunately, I have not been able to follow the development mailing list to monitor the progress, as you suggested, due to security constraints at Ericsson. > > I understand that you previously mentioned the Kafka release may require approximately two more weeks. As noted in my last email, we have a release delivery scheduled for the end of September. Therefore, I would like to check whether you see a possibility of having the Kafka release available within that timeframe. > > I really appreciate your response and support on this. > > //Mayank > > -----Original Message----- > From: Vivek Agarwal B <vivek.b.agarwal@ericsson.com> > Sent: 16 September 2026 05:05 PM > To: Matthias J. Sax <mjsax@apache.org>; users@kafka.apache.org > Cc: Ashish ...

RE: Kafka 4.4.0 formal release date -- Important

Hi @Matthias J. Sax, Unfortunately, I have not been able to follow the development mailing list to monitor the progress, as you suggested, due to security constraints at Ericsson. I understand that you previously mentioned the Kafka release may require approximately two more weeks. As noted in my last email, we have a release delivery scheduled for the end of September. Therefore, I would like to check whether you see a possibility of having the Kafka release available within that timeframe. I really appreciate your response and support on this. //Mayank -----Original Message----- From: Vivek Agarwal B <vivek.b.agarwal@ericsson.com> Sent: 16 September 2026 05:05 PM To: Matthias J. Sax <mjsax@apache.org>; users@kafka.apache.org Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Mayank Maheshwari M <mayank.m.maheshwari@ericsson.com> Subject: RE: Kafka 4.4.0 formal release date -- Important Hi Matthias, Do we now have a confirmed date for t...

RE: Kafka 4.4.0 formal release date -- Important

Hi Matthias, Do we now have a confirmed date for the formal release of Kafka 4.4.0? Regards Vivek -----Original Message----- From: Matthias J. Sax <mjsax@apache.org> Sent: 10 September 2026 02:49 To: users@kafka.apache.org; Vivek Agarwal B <vivek.b.agarwal@ericsson.com> Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Mayank Maheshwari M <mayank.m.maheshwari@ericsson.com> Subject: Re: Kafka 4.4.0 formal release date -- Important [You don't often get email from mjsax@apache.org. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] As an open source project, we don't have committed release dates. The page literally says "no earlier than": > meaning we expect to release no earlier than September 9 2026 The AK 4.4.0 release is in code freeze, and a first RC was cut. But some blocker bugs were found, and need to be fixed before the next RC can be prepared. If you want to monitor the progre...

Kafka jetty vulnerabilities fixes

Hello Kafka Team, Below are the vulnerabilities which are identified in Jetty v12.0.37. They are fixed in jetty version 12.0.38. Kafka 4.4.0 rc still uses Jetty 12.0.37, could you please confirm if the formal kafka 4.4.0 release will upgrade the jetty version to 12.0.38? * CVE-2026-12611 (HTTP/2 thread exhaustion DoS) * CVE-2026-19203 (HTTP Request Smuggling) * CVE-2026-19204 (WebSocket memory exhaustion DoS) Regards Vivek

jline related vulnerabilities in kafka

There are 4 Jline related vulnerabilities which are fixed in jline version 3.30.17. Kafka 4.4.0 rc still on jline 3.30.16. Please confirm whether kakfa 4.4.0 formal release will have upgrade jline version. The vulnerabilities are - https://github.com/jline/jline3/security/advisories/GHSA-7h86-pjwh-gpqj https://github.com/jline/jline3/security/advisories/GHSA-m935-wqpj-pvp3 https://github.com/jline/jline3/security/advisories/GHSA-6r3w-6jpj-x5w6 https://github.com/jline/jline3/security/advisories/GHSA-c87g-867h-cqr6 Regards Vivek

Kafka v4.3.0 zstd-jni related vulnerabilities

Hello Apache Kafka Team, In our product, kafka v4.3.0 is used. Below 3 Jli zstd-jni related vulnerabilities are reported on this kafka version - CVE-2026-87795 CVE-2026-87823 CVE-2026-87825 I see in Kafka 4.4.0 rc, zstd: "1.5.6-10" is included. However the fix for these 3 vulnerabilities is in Fixed version: 1.5.7-14 and later. Please confirm whether kafka 4.4.0 formal release will have fix for these vulnerabilities? Regards Vivek

Re: Kafka 4.4.0 formal release date -- Important

As an open source project, we don't have committed release dates. The page literally says "no earlier than": > meaning we expect to release no earlier than September 9 2026 The AK 4.4.0 release is in code freeze, and a first RC was cut. But some blocker bugs were found, and need to be fixed before the next RC can be prepared. If you want to monitor the progress more closely, you can follow the dev mailing list (or the corresponding email thread on the archive in case you don't want to subscribe). At this point, I would think we need _at least_ two more weeks... -Matthias On 9/8/26 9:52 PM, Mayank Maheshwari M via users wrote: > Hi Kafka Team, > > Appreciate your response to the email below. > > We have a release planned for the end of September and are planning to include this Kafka version with the vulnerability fixes in the release. > > //Mayank > > From: Vivek Agarwal B <vivek.b.agarwal@er...

Re: Kafka 4.4.0 formal release date

There is no better date than given on the wiki page. As an open source project, we don't have committed release dates. The page literally says "no earlier than": > meaning we expect to release no earlier than September 9 2026 The AK 4.4.0 release is in code freeze, and a first RC was cut. But some blocker bugs were found, and need to be fixed before the next RC can be prepared. If you want to monitor the progress more closely, you can follow the dev mailing list (or the corresponding email thread on the archive in case you don't want to subscribe). At this point, I would think we need _at least_ two more weeks... -Matthias On 9/8/26 10:20 PM, Apoorva Maheshwari via users wrote: > Hello Team, > > The Kafka 4.4.0 is not yet released. Can you please give confirmation on the Kafka release date? > > As per Kafka's plan 9th September is the probable release date. > > Release Plan 4.4.0 - Apache Kafka - ...

RE: Kafka 4.4.0 formal release date -- Important

Hi Kafka Team, Appreciate your response to the email below. We have a release planned for the end of September and are planning to include this Kafka version with the vulnerability fixes in the release. //Mayank From: Vivek Agarwal B <vivek.b.agarwal@ericsson.com> Sent: 08 September 2026 09:16 AM To: users@kafka.apache.org Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Mayank Maheshwari M <mayank.m.maheshwari@ericsson.com> Subject: Kafka 4.4.0 formal release date Hi, As per Release Plan 4.4.0 - Apache Kafka - Apache Software Foundation<https://cwiki.apache.org/confluence/spaces/KAFKA/pages/429064575/Release+Plan+4.4.0>, the formal release for Kafka 4.4.0 is planned for 9th Sep. Could you please confirm that the release date remains unchanged and that there are no updates to the current schedule? Regards Vivek

Kafka 4.4.0 formal release date

Hello Team, The Kafka 4.4.0 is not yet released. Can you please give confirmation on the Kafka release date? As per Kafka's plan 9th September is the probable release date. Release Plan 4.4.0 - Apache Kafka - Apache Software Foundation<https://cwiki.apache.org/confluence/spaces/KAFKA/pages/429064575/Release+Plan+4.4.0> Regards, Apoorva Maheshwari

Kafka 4.4.0 formal release date

Hi, As per Release Plan 4.4.0 - Apache Kafka - Apache Software Foundation<https://cwiki.apache.org/confluence/spaces/KAFKA/pages/429064575/Release+Plan+4.4.0>, the formal release for Kafka 4.4.0 is planned for 9th Sep. Could you please confirm that the release date remains unchanged and that there are no updates to the current schedule? Regards Vivek

Kafka neo4j vulnerabilities

Hi, Our security scan tools have detected following neo4j related vulnerabilities for below library present in kafka 4.3.0 /libs/activation-1.1.1.jar CVEs are - CVE-2021-34371 CVE-2026-1524 CVE-2026-1497 CVE-2026-1337 CVE-2026-1471 Please confirm if kafka is impacted due to this vulnerabilities. If yes, what is mitigation plan. Regards Vivek

Re: [DISCUSS] LogAppendTime can decrease after leader election

I haven't thought through this, but I'd be interested in seeing how this would affect windows that use Beam's KafkaIO withLogAppendTime (which assume LogAppendTime is monotonic afaik). It makes me wonder if that works correctly today. -Jon > On Sep 6, 2026, at 11:17 AM, Chia-Ping Tsai <chia7712@apache.org> wrote: > > Hi Alexander > > It's interesting and worth mulling it over. Would you mind opening a jira and KIP to propose this change? > > Best, > Chia-Ping > > On 2026/08/18 08:34:09 Alexander Neubeck wrote: >> Hi Kafka developers, >> >> KIP-32 describes LogAppendTime as monotonically increasing. However, the current implementation stamps records using the active leader’s local clock. >> >> After a leader election, the new leader’s clock may be behind the previous leader’s clock. In that case, newly appended records can receive a lower LogAppendTime than preceding records in th...

Re: [DISCUSS] LogAppendTime can decrease after leader election

Hi Alexander It's interesting and worth mulling it over. Would you mind opening a jira and KIP to propose this change? Best, Chia-Ping On 2026/08/18 08:34:09 Alexander Neubeck wrote: > Hi Kafka developers, > > KIP-32 describes LogAppendTime as monotonically increasing. However, the current implementation stamps records using the active leader’s local clock. > > After a leader election, the new leader’s clock may be behind the previous leader’s clock. In that case, newly appended records can receive a lower LogAppendTime than preceding records in the partition. > > A possible fix is for each partition leader to select: > > Plain text > > max(current broker time, previous LogAppendTime) > > > > The previous value can be recovered from the replicated log tail and maintained across follower appends, restart, truncation, and leader promotion. This guarantees nondecreasing timestamps without forcing a one-milli...

RE: Kafka v4.3.0 Jackson related vulnerabilities

Hi, As per below mentioned ticket, CVE-2026-68497 fix will be included in kafka v4.4.0<https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0> Is my understanding correct? Thanks Ashish Verma From: Gergely Harmadás <harmadasg@gmail.com> Sent: 31 August 2026 21:56 To: users@kafka.apache.org Cc: Ashish Verma V <ashish.v.verma@ericsson.com>; Vivek Agarwal B <vivek.b.agarwal@ericsson.com> Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities Hello Luke and Vivek, I have gone ahead and created KAFKA-21004<https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix (also opened a PR) Regards, Gergely On Mon, 31 Aug 2026 at 11:10, Luke Chen <showuon@gmail.com<mailto:showuon@gmail.com>> wrote: Hi Vivek, Thanks for reporting this issue. Could you please open a JIRA <http://issues.apache.org/jira/browse/KAFKA> ticket for this issue? And if possible, welcome to create a...

Re: Kafka v4.3.0 Jackson related vulnerabilities

Hello Luke and Vivek, I have gone ahead and created KAFKA-21004 <https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix (also opened a PR) Regards, Gergely On Mon, 31 Aug 2026 at 11:10, Luke Chen <showuon@gmail.com> wrote: > Hi Vivek, > > Thanks for reporting this issue. > Could you please open a JIRA > <http://issues.apache.org/jira/browse/KAFKA> ticket > for this issue? > And if possible, welcome to create a PR for it. > > From the current schedule, it should be included in v4.5.0. > > Thanks, > Luke > > On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < > users@kafka.apache.org> wrote: > > > Hi, > > > > In our product, kafka v4.3.0 is used. Below Jackson related > vulnerability > > is reported on this kafka version - > > > > CVE-2026-68497 > > This vulnerability is fixed in jackson databind v2.21.6. I se...

Re: Kafka v4.3.0 Jackson related vulnerabilities

Hi Vivek, Thanks for reporting this issue. Could you please open a JIRA <http://issues.apache.org/jira/browse/KAFKA> ticket for this issue? And if possible, welcome to create a PR for it. From the current schedule, it should be included in v4.5.0. Thanks, Luke On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < users@kafka.apache.org> wrote: > Hi, > > In our product, kafka v4.3.0 is used. Below Jackson related vulnerability > is reported on this kafka version - > > CVE-2026-68497 > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming > release kafka v4.4.0 bumped Jackson bind version to v2.21.5 > Please confirm which apache kafka upcoming versions will upgrade to > Jackson bind v2.21.6 > > Regards > Vivek > >

Kafka v4.3.0 Jackson related vulnerabilities

Hi, In our product, kafka v4.3.0 is used. Below Jackson related vulnerability is reported on this kafka version - CVE-2026-68497 This vulnerability is fixed in jackson databind v2.21.6. I see upcoming release kafka v4.4.0 bumped Jackson bind version to v2.21.5 Please confirm which apache kafka upcoming versions will upgrade to Jackson bind v2.21.6 Regards Vivek

setting up log4j2 for Kafka Provider

Good Afternoon, Am looking to control log4j2 output produced by Kafka...but am having a little difficultly getting this to work as expected. During the kafka producer startup I've added this command: -Dlog4j2.configurationFile=/<whatever>/kafka/producers/log4j2.properties I've created a log4j2.properties file as follows: # Root Logger rootLogger=INFO, STDERR # Direct log messages to stderr appender.console.type = Console appender.console.name = STDERR appender.console.layout.type = PatternLayout appender.console.layout.pattern = [%-5level] %d{yyyy-MM-dd HH:mm:ss.SSS} [%t] %C{1} - %msg%n Yet, when I look at STDERR am not seeing the desired messages. Do I need to configure slf4j instead or in conjunction? Anything I'm possibly doing wrong? Anyone with experience on customizing kafka message logging, will to chime in? Thank You, --Alex