Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- CONFSA-2025-06: CVE-2025-1948: Confluent Platform and Confluent Cloud Vulnerability - Denial of Service (DoS) due to improper handling of data by Jetty HTTP2 server
- CONFSA-2025-05: CVE-2025-8671, CVE-2025-5115, CVE-2025-55163: Confluent Platform and Confluent Cloud Vulnerability - “Made you reset” Denial of Service due to improper stream cancellation in HTTP/2 protocol
- CONFSA-2025-07: CVE-2025-58057: Confluent Platform and Confluent Cloud Vulnerability: Denial of Service (DoS) due to improper handling of data by Netty ZSTD decoder
- Security Release Notes for CFK 3.0.1
- Security Release Notes for CFK 2.11.3
- Security Release Notes for CFK 2.10.3
- Security Release Notes for CFK 2.9.7
- Security Release Notes for CP 8.0.1
- Security Release Notes for CP 7.9.3
- Security Release Notes for CP 7.8.4
- Security Release Notes for CP 7.7.5
- Security Release Notes for CP 7.6.7
- Security Release Notes for CP 7.5.10
- Security Release Notes for CP 7.4.11
- Security Release Notes for CP 7.3.14
- CONFSA-2025-04: CVE-2025-27817: Confluent Platform and Confluent Cloud: Arbitrary File Read and Server-Side Request Forgery (SSRF) Vulnerability via unauthorized changes to Kafka Client SASL/OAUTHBEARER configuration
- CONFSA-2025-02: CVE-2025-27818, CVE-2025-27819: Confluent Platform and Confluent Cloud: Certain components vulnerable to deserialization of untrusted data
- Security Release Notes for CFK 2.11.2
- Security Release Notes for CFK 2.11.1
- Security Release Notes for CFK 2.10.2
- Security Release Notes for CFK 2.9.6
- Security Release Notes for CP 7.9.2
- Security Release Notes for CP 7.9.1
- Security Release Notes for CP 7.8.3
- Security Release Notes for CP 7.7.4
- Security Release Notes for CP 7.6.6
- Security Release Notes for CP 7.5.9
- Security Release Notes for CP 7.4.10
- Security Release Notes for CP 7.3.13
- Security Release Notes for CP 7.2.15