[ 
https://issues.apache.org/jira/browse/KAFKA-20871?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Mickael Maison resolved KAFKA-20871.
------------------------------------
    Resolution: Invalid

Kafka has already been updated to use Jetty 12.0.37, see 
https://issues.apache.org/jira/browse/KAFKA-20840

> Upgrade Jetty 12.0.34 dependencies in Kafka to address multiple security 
> vulnerabilities
> ----------------------------------------------------------------------------------------
>
>                 Key: KAFKA-20871
>                 URL: https://issues.apache.org/jira/browse/KAFKA-20871
>             Project: Kafka
>          Issue Type: Bug
>    Affects Versions: 4.3.1
>            Reporter: Mangesh Dushman
>            Priority: Major
>
> The Kafka component currently includes Jetty *12.0.34* libraries that are 
> affected by the following security vulnerabilities:
> ||CVE||Component||Current Version||
> |CVE-2026-6790|jetty-server|12.0.34|
> |CVE-2026-10050|jetty-security|12.0.34|
> |CVE-2026-10051|jetty-server|12.0.34|
> |CVE-2026-8384|jetty-util|12.0.34|



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to