Confluent Platform patch release version 7.5.16 contains fixes that resolve vulnerabilities in Confluent owned components and in various dependency versions depended upon by Confluent Platform components.
Security Vulnerabilities
Confluent Platform 7.5.16 patch release contains fixes for the following security vulnerabilities:
|
Vulnerability Reference |
CVSS |
Affected Components |
Resolution |
|
|
CVE-2026-50020 - 5.3 CVE-2026-50560 - 5.3 CVE-2026-45416 - 7.5 CVE-2026-44893 - 7.5 CVE-2026-48059 - 7.5 |
Netty |
This issue has been fixed in Confluent Platform version 7.5.16. |
5.9 |
Kafka |
This issue has been fixed in Confluent Platform version 7.5.16. Please review the additional required configuration in Confluent Platform documentation below: https://docs.confluent.io/platform/7.5/multi-dc-deployments/cluster-linking/security.html#restrict-cluster-link-token-handler-urls |
|
5.7 |
Schema Registry |
This issue has been fixed in Confluent Platform version 7.5.16. Please review the additional required configuration in Confluent Platform documentation below: https://docs.confluent.io/platform/7.5/schema-registry/installation/config.html#schema-providers-json-fetch-remote-schemas |
|
|
CONFSA-2026-16 CONFSA-2026-17 CONFSA-2026-18 CONFSA-2026-19 CONFSA-2026-20 |
5.7 |
Kafka |
These issues have been fixed in Confluent Platform version 7.5.16. Additional information will be published in coordination with the Apache Software Foundation along with upcoming Kafka release |
More information in the following Confluent Security Advisories:
- CONFSA-2026-13: Multiple Netty Vulnerabilities
- CONFSA-2026-14: Server-Side Request Forgery (SSRF) to internal endpoints via cluster link token login handler configuration
- CONFSA-2026-15: Denial of Service in Schema Registry via external schema references
- CONFSA-2026-16 , CONFSA-2026-17, CONFSA-2026-18, CONFSA-2026-19, CONFSA-2026-20:Multiple Kafka Vulnerabilities
Resolved hygiene issues in 3rd party dependencies
The following package upgrades are included in this release version and are made available to enhance the security hygiene of Confluent software, as no exploitable vector was identified for the CVEs present in impacted packages. We have provided the CVE identifiers to assist customers with analysis.
CVE |
CVSS |
Impacted Package Version |
Upgraded Package Version |
8.7 |
io.netty:netty-resolver-dns < 4.1.135.Final |
io.netty:netty-resolver-dns = 4.1.135.Final |
|
8.7 |
io.netty:netty-resolver-dns < 4.1.135.Final |
io.netty:netty-resolver-dns = 4.1.135.Final |
|
8.1 |
io.netty:netty-handler < 4.1.135.Final |
io.netty:netty-handler = 4.1.135.Final io.netty:netty-handler = 4.1.136.Final |
|
7.8 |
stdlib < 1.26.5 |
stdlib = 1.26.5 |
|
7.5 |
io.netty:netty-codec-redis < 4.1.135.Final |
io.netty:netty-codec-redis = 4.1.135.Final |
|
7.5 |
io.netty:netty-codec-redis < 4.1.135.Final |
io.netty:netty-codec-redis = 4.1.135.Final |
|
7.5 |
io.netty:netty-codec-haproxy < 4.1.135.Final |
io.netty:netty-codec-haproxy = 4.1.135.Final |
|
7.5 |
io.netty:netty-handler < 4.1.135.Final |
io.netty:netty-handler = 4.1.135.Final io.netty:netty-handler = 4.1.136.Final |
|
7.5 |
io.netty:netty-transport-sctp < 4.1.135.Final |
io.netty:netty-transport-sctp = 4.1.135.Final |
|
7.5 |
io.netty:netty-codec-redis < 4.1.135.Final |
io.netty:netty-codec-redis = 4.1.135.Final |
|
7.5 |
io.netty:netty-codec-haproxy < 4.1.135.Final |
io.netty:netty-codec-haproxy = 4.1.135.Final |
|
7.5 |
io.netty:netty-handler < 4.1.135.Final |
io.netty:netty-handler = 4.1.135.Final io.netty:netty-handler = 4.1.136.Final |
|
7.5 |
io.netty:netty-codec-redis < 4.1.135.Final |
io.netty:netty-codec-redis = 4.1.135.Final |
|
7.5 |
pyasn1 < 0.6.4 |
pyasn1 = 0.6.4 |
|
7.5 |
pyasn1 < 0.6.4 |
pyasn1 = 0.6.4 |
|
7.5 |
pyasn1 < 0.6.4 |
pyasn1 = 0.6.4 |
|
6.8 |
io.netty:netty-resolver-dns < 4.1.135.Final |
io.netty:netty-resolver-dns = 4.1.135.Final |
|
6.1 |
setuptools < 83.0.0 |
setuptools = 83.0.0 |
|
5.3 |
stdlib < 1.26.5 |
stdlib = 1.26.5 |
|
5.3 |
io.netty:netty-codec-http2 < 4.1.135.Final |
io.netty:netty-codec-http2 = 4.1.135.Final |
|
5.3 |
io.netty:netty-codec-http2 < 4.1.135.Final |
io.netty:netty-codec-http2 = 4.1.135.Final |
|
5.3 |
io.netty:netty-codec-http < 4.1.135.Final |
io.netty:netty-codec-http = 4.1.135.Final |
|
5.3 |
io.netty:netty-codec-http2 < 4.1.135.Final |
io.netty:netty-codec-http2 = 4.1.135.Final |
|
4.0 |
io.netty:netty-transport-native-epoll < 4.1.135.Final |
io.netty:netty-transport-native-epoll = 4.1.135.Final io.netty:netty-transport-native-epoll = 4.1.136.Final |
|
4.0 |
io.netty:netty-transport-native-kqueue < 4.1.135.Final |
io.netty:netty-transport-native-kqueue = 4.1.135.Final |
This patch release uses Red Hat Universal Base Image 8 Minimal version 8.10-1784730826.