Joshua Wisniewski created KAFKA-21032:
-----------------------------------------
Summary: Please update kafka-clients.jar to address CVE-2026-59949
Key: KAFKA-21032
URL: https://issues.apache.org/jira/browse/KAFKA-21032
Project: Kafka
Issue Type: Improvement
Components: security
Affects Versions: 4.3.1
Environment: x86 Linux
Reporter: Joshua Wisniewski
kafka-clients.jar depends on lz4-java which has the mentioned CVE
[https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies
|https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies]
Please update the kafka-clients.jar to ship with lz4-java 1.11.1 or greater to
satisfy security scans.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)