Thanks for the information.

Regards,
James

-----Original Message-----
From: Gergely Harmadás <[email protected]> 
Sent: 14 August 2026 16:58
To: [email protected]
Subject: [EXTERNAL] Re: CVE-2026-59949 – Impact on Kafka (lz4-java)

Hi James,

The update to 1.11.1 was covered in KAFKA-20842 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20842&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=Rtskq3UpzxYUDRvG-RkTH59cAW9Z8_015-CxCexEG0M&e=
 >. The CVE fix will be included in the upcoming Kafka 4.4 release which is 
targeted for September according to the Release Plan 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__cwiki.apache.org_confluence_spaces_KAFKA_pages_429064575_Release-2BPlan-2B4.4.0&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=sf7VZBPkv6KzQsEateGr841NKrq0epSCQO05WlzYBOA&e=
 >.
There was also a backport to the 4.3 branch which means the CVE fix will be 
included in a subsequent release, but AFAIK there is no planned date yet for 
4.3.2.

As a side-note I have noticed there is new security release for lz4, created 
KAFKA-20937 
<https://urldefense.proofpoint.com/v2/url?u=https-3A__issues.apache.org_jira_browse_KAFKA-2D20937&d=DwIFaQ&c=BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=1rC8kX7_JaOzD_UXptNGM7VeglnyMjTuXu0WympUDaU&e=
 > to track the update.

Best regards,
Gergely

On Thu, 13 Aug 2026 at 05:59, JAMES JOSE <[email protected]> wrote:

> Hi Team,
>
> As per the GitHub advisory for GHSA-xx22-p4ch-683r (CVE-2026-59949), 
> lz4-java versions up to and including 1.11.0 are affected, with the 
> issue fixed in version 1.11.1. GitHub Advisory – GHSA-xx22-p4ch-683r< 
> https://urldefense.proofpoint.com/v2/url?u=https-3A__github.com_adviso
> ries_GHSA-2Dxx22-2Dp4ch-2D683r-3Futm-5Fsource-3Dchatgpt.com&d=DwIFaQ&c
> =BSDicqBQBDjDI9RkVyTcHQ&r=wFuRXeZ1jY-k5xudtTTZ60tgwyI060iX_RvaTA5osQs&
> m=1D8DzNrAXlo6oFOad6b3jmLZxFQNXN36k_qrhHmAnqsr_1M7DWODVs6nR5clcUX4&s=0
> leyUvEfu72D5H17gecX__uM3pEjIrAPlZfVtSbZ0CI&e= >
>
> We understand that the latest Kafka version currently uses lz4-java-1.10.2.
>
> Could you please confirm whether this means Kafka is affected by
> CVE-2026-59949 and whether Kafka needs to be updated to use lz4-java 
> 1.11.1 or later?
>
> If a Kafka update is required, could you also let us know whether 
> there is a planned Kafka release that will include the fixed version, 
> and the expected release date?
>
> Thanks,
> James
>
>

Reply via email to