Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CFK 2.11.4
- Security Release Notes for CFK 2.10.4
- Security Release Notes for CFK 2.9.8
- Security Release Notes for CP 8.1.1
- Security Release Notes for CP 8.0.3
- Security Release Notes for CP 8.0.2
- Security Release Notes for CP 7.9.5
- Security Release Notes for CP 7.7.7
- Security Release Notes for CP 7.8.6
- Security Release Notes for CP 7.9.4
- Security Release Notes for CP 7.7.6
- Security Release Notes for CP 7.6.9
- Security Release Notes for CP 7.6.8
- Security Release Notes for CP 7.5.12
- Security Release Notes for CP 7.5.11
- Security Release Notes for CP 7.4.13
- Security Release Notes for CP 7.4.12
- CONFSA-2025-08: Insecure default configuration in Confluent Platform deployed via CFK in PLAIN SASL mode
- CONFSA-2025-06: CVE-2025-1948: Confluent Platform and Confluent Cloud Vulnerability - Denial of Service (DoS) due to improper handling of data by Jetty HTTP2 server
- CONFSA-2025-05: CVE-2025-8671, CVE-2025-5115, CVE-2025-55163: Confluent Platform and Confluent Cloud Vulnerability - “Made you reset” Denial of Service due to improper stream cancellation in HTTP/2 protocol
- CONFSA-2025-07: CVE-2025-58057: Confluent Platform and Confluent Cloud Vulnerability: Denial of Service (DoS) due to improper handling of data by Netty ZSTD decoder
- Security Release Notes for CFK 3.0.1
- Security Release Notes for CFK 2.11.3
- Security Release Notes for CFK 2.10.3
- Security Release Notes for CFK 2.9.7
- Security Release Notes for CP 8.0.1
- Security Release Notes for CP 7.9.3
- Security Release Notes for CP 7.8.4
- Security Release Notes for CP 7.7.5
- Security Release Notes for CP 7.6.7