Gergely Harmadás created KAFKA-21139:
----------------------------------------

             Summary: Update Jetty to 12.0.39
                 Key: KAFKA-21139
                 URL: https://issues.apache.org/jira/browse/KAFKA-21139
             Project: Kafka
          Issue Type: Task
            Reporter: Gergely Harmadás
            Assignee: Gergely Harmadás


[https://jetty.org/security.html] lists 3 CVEs impacting the current jetty 
version used in Kafka (12.0.37)
 * 
[CVE-2026-19204|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19204]
 * 
[CVE-2026-19203|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19203]
 * 
[CVE-2026-12611|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12611]

Upgrading to latest jetty version to mitigate the reported CVEs



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to