Hello Team,


Could you please confirm the plan to release a new Kafka version that includes 
fixes for vulnerabilities identified primarily in transient dependencies such 
as Jetty, log4j, Jackson, and a few others?



Below is the list of identified vulnerabilities for reference:



CVE-2025-67030

CVE-2026-39882

CVE-2026-41078

CVE-2026-40894

CVE-2026-34477

CVE-2026-34478

CVE-2026-34479

CVE-2026-34480

CVE-2026-34481

CVE-2026-1605

CVE-2025-11143

CVE-2026-2332

CVE-2026-5795

GHSA-72hv-8253-57qq



Regards
Apoorva Maheshwari

Reply via email to