Hi, As per below mentioned ticket, CVE-2026-68497 fix will be included in kafka v4.4.0<https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0> Is my understanding correct?
Thanks Ashish Verma From: Gergely Harmadás <[email protected]> Sent: 31 August 2026 21:56 To: [email protected] Cc: Ashish Verma V <[email protected]>; Vivek Agarwal B <[email protected]> Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities Hello Luke and Vivek, I have gone ahead and created KAFKA-21004<https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix (also opened a PR) Regards, Gergely On Mon, 31 Aug 2026 at 11:10, Luke Chen <[email protected]<mailto:[email protected]>> wrote: Hi Vivek, Thanks for reporting this issue. Could you please open a JIRA <http://issues.apache.org/jira/browse/KAFKA> ticket for this issue? And if possible, welcome to create a PR for it. From the current schedule, it should be included in v4.5.0. Thanks, Luke On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < [email protected]<mailto:[email protected]>> wrote: > Hi, > > In our product, kafka v4.3.0 is used. Below Jackson related vulnerability > is reported on this kafka version - > > CVE-2026-68497 > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming > release kafka v4.4.0 bumped Jackson bind version to v2.21.5 > Please confirm which apache kafka upcoming versions will upgrade to > Jackson bind v2.21.6 > > Regards > Vivek > >
