Skip to content

KAFKA-20349: Upgrade to ZooKeeper 3.8.6 - fix CVE-2026-24308#21858

Open
mjschwaiger wants to merge 1 commit intoapache:3.9from
mjschwaiger:KAFKA-20349-Upgrade-to-ZooKeeper-3.8.6
Open

KAFKA-20349: Upgrade to ZooKeeper 3.8.6 - fix CVE-2026-24308#21858
mjschwaiger wants to merge 1 commit intoapache:3.9from
mjschwaiger:KAFKA-20349-Upgrade-to-ZooKeeper-3.8.6

Conversation

@mjschwaiger
Copy link
Copy Markdown

@mjschwaiger mjschwaiger commented Mar 24, 2026

Update dependency ZooKeeper "org.apache.zookeeper:zookeeper" from 3.8.4 to 3.8.6 to fix CVE-2026-24308 in kafka_2.13:3.9.2.
https://www.cve.org/CVERecord?id=CVE-2026-24308
https://zookeeper.apache.org/security.html#CVE-2026-24308

Goal: new release of Kafka 3.9.x (e.g., 3.9.3) including this fix

Reviewers: Chia-Ping Tsai chia7712@gmail.com

@mjschwaiger mjschwaiger changed the title KAFKA-20349 Upgrade to ZooKeeper 3.8.6 - fix CVE-2026-24308 KAFKA-20349: Upgrade to ZooKeeper 3.8.6 - fix CVE-2026-24308 Mar 24, 2026
@chia7712
Copy link
Copy Markdown
Member

zookeeper 3.8.5 had updated slf4j to 2.0.13 apache/zookeeper@66202cb

Excluding slf4j-api from ZK in build.gradle. It is safe since ZK hasn't adopted SLF4J fluent APIs yet.

      implementation libs.dropwizardMetrics
      exclude module: 'slf4j-log4j12'
      exclude module: 'slf4j-api' <--- this one
      exclude module: 'log4j'

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants