[ 
https://issues.apache.org/jira/browse/KAFKA-21032?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Mickael Maison resolved KAFKA-21032.
------------------------------------
    Resolution: Duplicate

> Please update kafka-clients.jar to address CVE-2026-59949
> ---------------------------------------------------------
>
>                 Key: KAFKA-21032
>                 URL: https://issues.apache.org/jira/browse/KAFKA-21032
>             Project: Kafka
>          Issue Type: Improvement
>          Components: security
>    Affects Versions: 4.3.1
>         Environment: x86 Linux
>            Reporter: Joshua Wisniewski
>            Priority: Critical
>
> kafka-clients.jar depends on lz4-java which has the mentioned CVE 
> [https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies
>   
> |https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies]
> Please update the kafka-clients.jar to ship with lz4-java 1.11.1 or greater 
> to satisfy security scans.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to