Hi,

As per below mentioned ticket, CVE-2026-68497 fix will be included in kafka 
v4.4.0<https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0>
Is my understanding correct?

Thanks
Ashish Verma
From: Gergely Harmadás <[email protected]>
Sent: 31 August 2026 21:56
To: [email protected]
Cc: Ashish Verma V <[email protected]>; Vivek Agarwal B 
<[email protected]>
Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities

Hello Luke and Vivek,

I have gone ahead and created 
KAFKA-21004<https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE 
fix (also opened a PR)

Regards,
Gergely

On Mon, 31 Aug 2026 at 11:10, Luke Chen 
<[email protected]<mailto:[email protected]>> wrote:
Hi Vivek,

Thanks for reporting this issue.
Could you please open a JIRA
<http://issues.apache.org/jira/browse/KAFKA> ticket
for this issue?
And if possible, welcome to create a PR for it.

From the current schedule, it should be included in v4.5.0.

Thanks,
Luke

On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users <
[email protected]<mailto:[email protected]>> wrote:

> Hi,
>
> In our product, kafka v4.3.0 is used. Below  Jackson related vulnerability
> is reported on this kafka version -
>
> CVE-2026-68497
> This vulnerability is fixed in jackson databind v2.21.6. I see upcoming
> release kafka v4.4.0 bumped Jackson bind version to v2.21.5
> Please confirm which apache kafka upcoming versions will upgrade to
> Jackson bind v2.21.6
>
> Regards
> Vivek
>
>

Reply via email to