Joshua Wisniewski created KAFKA-21032:
-----------------------------------------

             Summary: Please update kafka-clients.jar to address CVE-2026-59949
                 Key: KAFKA-21032
                 URL: https://issues.apache.org/jira/browse/KAFKA-21032
             Project: Kafka
          Issue Type: Improvement
          Components: security
    Affects Versions: 4.3.1
         Environment: x86 Linux
            Reporter: Joshua Wisniewski


kafka-clients.jar depends on lz4-java which has the mentioned CVE 
[https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies
  
|https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients/4.3.1/dependencies]

Please update the kafka-clients.jar to ship with lz4-java 1.11.1 or greater to 
satisfy security scans.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to