Hello Apache Kafka Team,


In our product, kafka v4.3.0 is used. Below 3 Jli zstd-jni related 
vulnerabilities are reported on this kafka version -



CVE-2026-87795

CVE-2026-87823

CVE-2026-87825


I see in Kafka 4.4.0 rc, zstd: "1.5.6-10" is included. However the fix for 
these 3 vulnerabilities is in Fixed version: 1.5.7-14 and later.

Please confirm whether kafka 4.4.0 formal release will have fix for these 
vulnerabilities?

Regards
Vivek

Reply via email to