Hello Luke and Vivek,

I have gone ahead and created KAFKA-21004
<https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix
(also opened a PR)

Regards,
Gergely

On Mon, 31 Aug 2026 at 11:10, Luke Chen <[email protected]> wrote:

> Hi Vivek,
>
> Thanks for reporting this issue.
> Could you please open a JIRA
> <http://issues.apache.org/jira/browse/KAFKA> ticket
> for this issue?
> And if possible, welcome to create a PR for it.
>
> From the current schedule, it should be included in v4.5.0.
>
> Thanks,
> Luke
>
> On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users <
> [email protected]> wrote:
>
> > Hi,
> >
> > In our product, kafka v4.3.0 is used. Below  Jackson related
> vulnerability
> > is reported on this kafka version -
> >
> > CVE-2026-68497
> > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming
> > release kafka v4.4.0 bumped Jackson bind version to v2.21.5
> > Please confirm which apache kafka upcoming versions will upgrade to
> > Jackson bind v2.21.6
> >
> > Regards
> > Vivek
> >
> >
>

Reply via email to