[
https://issues.apache.org/jira/browse/KAFKA-21020?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18114230#comment-18114230
]
Harsh Vasava edited comment on KAFKA-21020 at 9/11/26 12:51 PM:
----------------------------------------------------------------
Hi [~shubhigupta] , I’d like to work on this issue. Could you please assign it
to me?
was (Author: JIRAUSER314405):
Hi @Shubhi Gupta, I’d like to work on this issue. Could you please assign it to
me?
> Fix CVE-2026-56740: Upgrade jline from 3.30.16 to 4.2.1
> -------------------------------------------------------
>
> Key: KAFKA-21020
> URL: https://issues.apache.org/jira/browse/KAFKA-21020
> Project: Kafka
> Issue Type: Bug
> Reporter: Shubhi Gupta
> Priority: Critical
> Labels: security
>
> A *High-severity vulnerability (CVE-2026-56740)* has been identified in
> {{org.jline:jline-remote-telnet}} versions prior to 4.2.1. The vulnerable jar
> ({{{}jline-3.30.4.jar{}}} / {{{}jline-3.30.16{}}}) is shipped inside the
> Kafka release tarball under {{{}/opt/kafka/libs/{}}}, exposing all Docker
> images built from that tarball to the vulnerability.
> The fix upgrades {{org.jline}} to version *4.2.1* — the first release line in
> which {{jline-remote-telnet}} is patched — and replaces one deprecated API
> call that became a compile-time error under {{{}-Werror{}}}.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)