Package
kafka-3.7
Component
kafka-clients
Latest update
8.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Apache Kafka has not backported the fix for GHSA-5qcv-4rpc-jp93 to this release stream.
Vulnerable range per advisory: >= 2.8.0, < 3.9.2 (for the 3.x line). Fix landed in:
No 3.7.3 or 3.8.x patch release exists or is planned by Apache. The original fix on trunk is apache/kafka#21065 (KAFKA-19012). Affected component: kafka-clients (Maven: org.apache.kafka:kafka-clients).
Consumers requiring this fix should migrate to a kafka 3.9.x or later stream.
Status