Joshua Wisniewski created KAFKA-21099:
-----------------------------------------

             Summary: CVE-2026-90559 snappy-java vulnerability
                 Key: KAFKA-21099
                 URL: https://issues.apache.org/jira/browse/KAFKA-21099
             Project: Kafka
          Issue Type: Bug
          Components: security
    Affects Versions: 4.3.1
            Reporter: Joshua Wisniewski


kafka-clients depends on snappy-java.  snappy-java has CVE 
[https://nvd.nist.gov/vuln/detail/cve-2026-90559] There is no fixed version of 
snappy-java discussed but a proactive change to the code is recommended.  Is 
there any intention to announce that these proactive changes have been made to 
kafka-clients to address this CVE?  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to