[
https://issues.apache.org/jira/browse/KAFKA-21032?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Mickael Maison resolved KAFKA-21032.
------------------------------------
Resolution: Duplicate
> Please update kafka-clients.jar to address CVE-2026-59949
> ---------------------------------------------------------
>
> Key: KAFKA-21032
> URL: https://issues.apache.org/jira/browse/KAFKA-21032
> Project: Kafka
> Issue Type: Improvement
> Components: security
> Affects Versions: 4.3.1
> Environment: x86 Linux
> Reporter: Joshua Wisniewski
> Priority: Critical
>
> kafka-clients.jar depends on lz4-java which has the mentioned CVE
> [https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies
>
> |https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies]
> Please update the kafka-clients.jar to ship with lz4-java 1.11.1 or greater
> to satisfy security scans.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)