Confluent Platform patch release version 7.9.10 contains fixes that resolve vulnerabilities in Confluent owned components and in various dependency versions depended upon by Confluent Platform components.
Security Vulnerabilities
Confluent Platform 7.9.10 patch release contains fixes for the following security vulnerabilities:
Vulnerability |
CVSS |
Affected Components |
Resolution |
5.7 |
ksqlDB | This issue has been fixed in Confluent Platform version 7.9.10. |
More information in the following Confluent Security Advisories:
- CONFSA-2026-21: Missing per-user authorization check in ksqlDB /query-stream pull queries
Resolved hygiene issues in 3rd party dependencies
The following package upgrades are included in this release version and are made available to enhance the security hygiene of Confluent software, as no exploitable vector was identified for the CVEs present in impacted packages. We have provided the CVE identifiers to assist customers with analysis.
CVE |
CVSS |
Impacted Package Version |
Upgraded Package Version |
9.8 |
org.apache.mina:mina-core < 2.0.29 org.apache.mina:mina-core < 2.2.8 |
org.apache.mina:mina-core = 2.0.29 org.apache.mina:mina-core = 2.2.9 |
|
9.8 |
io.netty:netty-codec-xml < 4.1.136.Final |
io.netty:netty-codec-xml = 4.1.137.Final |
|
9.1 |
org.eclipse.jetty:jetty-security < 9.4.63 |
org.eclipse.jetty:jetty-security = 9.4.63 |
|
9.1 |
com.azure:azure-security-keyvault-keys < 4.10.6 |
com.azure:azure-security-keyvault-keys = 4.10.6 |
|
8.7 |
com.fasterxml.jackson.core:jackson-core < 2.18.8 |
com.fasterxml.jackson.core:jackson-core = 2.18.9 |
|
8.2 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
8.1 |
com.fasterxml.jackson.core:jackson-databind < 2.18.8 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
8.1 |
com.fasterxml.jackson.core:jackson-databind < 2.18.8 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
8.0 |
pip < 26.1.2 |
pip = 26.2.1 |
|
7.5 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
7.5 |
urllib3 < 2.7.0 |
urllib3 = 2.7.0 |
|
7.5 |
io.netty:netty-codec-stomp < 4.1.136.Final |
io.netty:netty-codec-stomp = 4.1.137.Final |
|
7.5 |
com.squareup.wire:wire-runtime-jvm < 6.3.0 com.squareup.wire:wire-runtime-jvm < 7.0.0-alpha03 |
com.squareup.wire:wire-runtime-jvm = 6.4.5 |
|
7.5 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
7.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec-haproxy < 4.1.136.Final |
io.netty:netty-codec-haproxy = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec-http2 < 4.1.136.Final |
io.netty:netty-codec-http2 = 4.1.136.Final io.netty:netty-codec-http2 = 4.1.137.Final |
|
7.5 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
7.5 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
7.5 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
7.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
7.5 |
io.netty:netty-codec < 4.1.136.Final |
io.netty:netty-codec = 4.1.136.Final io.netty:netty-codec = 4.1.137.Final |
|
7.5 |
io.netty:netty-transport-sctp < 4.1.137.Final |
io.netty:netty-transport-sctp = 4.1.137.Final |
|
7.5 |
cryptography < 49.0.0 |
cryptography = Removed |
|
7.5 |
io.netty:netty-codec-xml < 4.1.136.Final |
io.netty:netty-codec-xml = 4.1.137.Final |
|
7.5 |
cryptography < 48.0.1 |
cryptography = Removed |
|
7.4 |
io.netty:netty-handler-ssl-ocsp < 4.1.136.Final |
io.netty:netty-handler-ssl-ocsp = 4.1.137.Final |
|
7.4 |
io.netty:netty-handler-ssl-ocsp < 4.1.136.Final |
io.netty:netty-handler-ssl-ocsp = 4.1.137.Final |
|
7.4 |
io.netty:netty-handler-ssl-ocsp < 4.1.136.Final |
io.netty:netty-handler-ssl-ocsp = 4.1.137.Final |
|
7.4 |
cryptography < 49.0.0 |
cryptography = Removed |
|
6.5 |
pip < 26.2.0 |
pip = 26.2.1 |
|
6.5 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
6.5 |
io.netty:netty-codec-redis < 4.1.136.Final |
io.netty:netty-codec-redis = 4.1.137.Final |
|
6.5 |
com.fasterxml.jackson.core:jackson-databind < 2.18.8 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
6.5 |
com.fasterxml.jackson.core:jackson-databind < 2.18.9 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
6.5 |
io.netty:netty-codec-stomp < 4.1.136.Final |
io.netty:netty-codec-stomp = 4.1.137.Final |
|
6.5 |
at.yawk.lz4:lz4-java < 1.11.1 |
at.yawk.lz4:lz4-java = 1.11.1 |
|
6.5 |
com.fasterxml.jackson.core:jackson-databind < 2.18.9 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
6.1 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
5.9 |
stdlib < 1.27.0-rc.3 |
stdlib = 1.27.1 |
|
5.9 |
cryptography < 50.0.0 |
cryptography = Removed |
|
5.8 |
pip < 26.1 |
pip = 26.2.1 |
|
5.7 |
io.netty:netty-codec-http < 4.1.136.Final |
io.netty:netty-codec-http = 4.1.136.Final io.netty:netty-codec-http = 4.1.137.Final |
|
5.5 |
io.netty:netty-codec-haproxy < 4.1.136.Final |
io.netty:netty-codec-haproxy = 4.1.137.Final |
|
5.3 |
urllib3 < 2.7.0 |
urllib3 = 2.7.0 |
|
5.3 |
com.fasterxml.jackson.core:jackson-databind < 2.18.8 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
5.3 |
com.fasterxml.jackson.core:jackson-databind < 2.18.9 |
com.fasterxml.jackson.core:jackson-databind = 2.18.9 |
|
5.3 |
io.netty:netty-codec-http2 < 4.1.136.Final |
io.netty:netty-codec-http2 = 4.1.136.Final io.netty:netty-codec-http2 = 4.1.137.Final |
|
5.3 |
io.netty:netty-codec-dns < 4.1.136.Final |
io.netty:netty-codec-dns = 4.1.136.Final io.netty:netty-codec-dns = 4.1.137.Final |
|
5.0 |
pip < 26.1 |
pip = 26.2.1 |
|
4.4 |
requests < 2.33.0 |
requests = 2.33.1 requests = 2.34.2 |
|
4.0 |
tuf < 7.0.0 |
tuf = Removed |
This patch release uses Red Hat Universal Base Image 8 Minimal version 8.10-1789361795.