Yes, it will be included in v4.4.0 as shown. Thanks, Luke
On Wed, Sep 2, 2026 at 1:39 PM Ashish Verma V via users < [email protected]> wrote: > Hi, > > As per below mentioned ticket, CVE-2026-68497 fix will be included in > kafka v4.4.0< > https://issues.apache.org/jira/issues/?jql=project+%3D+KAFKA+AND+fixVersion+%3D+4.4.0 > > > Is my understanding correct? > > Thanks > Ashish Verma > From: Gergely Harmadás <[email protected]> > Sent: 31 August 2026 21:56 > To: [email protected] > Cc: Ashish Verma V <[email protected]>; Vivek Agarwal B < > [email protected]> > Subject: Re: Kafka v4.3.0 Jackson related vulnerabilities > > Hello Luke and Vivek, > > I have gone ahead and created KAFKA-21004< > https://issues.apache.org/jira/browse/KAFKA-21004> to track the CVE fix > (also opened a PR) > > Regards, > Gergely > > On Mon, 31 Aug 2026 at 11:10, Luke Chen <[email protected]<mailto: > [email protected]>> wrote: > Hi Vivek, > > Thanks for reporting this issue. > Could you please open a JIRA > <http://issues.apache.org/jira/browse/KAFKA> ticket > for this issue? > And if possible, welcome to create a PR for it. > > From the current schedule, it should be included in v4.5.0. > > Thanks, > Luke > > On Mon, Aug 31, 2026 at 5:40 PM Vivek Agarwal B via users < > [email protected]<mailto:[email protected]>> wrote: > > > Hi, > > > > In our product, kafka v4.3.0 is used. Below Jackson related > vulnerability > > is reported on this kafka version - > > > > CVE-2026-68497 > > This vulnerability is fixed in jackson databind v2.21.6. I see upcoming > > release kafka v4.4.0 bumped Jackson bind version to v2.21.5 > > Please confirm which apache kafka upcoming versions will upgrade to > > Jackson bind v2.21.6 > > > > Regards > > Vivek > > > > >
