Yes, it will be included in v4.4.0 as shown.

Thanks,
Luke

On Wed, Sep 2, 2026 at 1:39 PM Ashish Verma V via users <
[email protected]> wrote:

> Hi,
>
> As per below mentioned ticket, CVE-2026-68497 fix will be included in
> kafka v4.4.0<
> https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0
> >
> Is my understanding correct?
>
> Thanks
> Ashish Verma
> From: Gergely Harmadás <[email protected]>
> Sent: 31 August 2026 21:56
> To: [email protected]
> Cc: Ashish Verma V <[email protected]>; Vivek Agarwal B <
> [email protected]>
> Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities
>
> Hello Luke and Vivek,
>
> I have gone ahead and created KAFKA-21004<
> https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix
> (also opened a PR)
>
> Regards,
> Gergely
>
> On Mon, 31 Aug 2026 at 11:10, Luke Chen <[email protected]<mailto:
> [email protected]>> wrote:
> Hi Vivek,
>
> Thanks for reporting this issue.
> Could you please open a JIRA
> <http://issues.apache.org/jira/browse/KAFKA> ticket
> for this issue?
> And if possible, welcome to create a PR for it.
>
> From the current schedule, it should be included in v4.5.0.
>
> Thanks,
> Luke
>
> On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users <
> [email protected]<mailto:[email protected]>> wrote:
>
> > Hi,
> >
> > In our product, kafka v4.3.0 is used. Below  Jackson related
> vulnerability
> > is reported on this kafka version -
> >
> > CVE-2026-68497
> > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming
> > release kafka v4.4.0 bumped Jackson bind version to v2.21.5
> > Please confirm which apache kafka upcoming versions will upgrade to
> > Jackson bind v2.21.6
> >
> > Regards
> > Vivek
> >
> >
>

Reply via email to