Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CP 7.5.10
- Security Release Notes for CP 7.4.11
- Security Release Notes for CP 7.3.14
- CONFSA-2025-04: CVE-2025-27817: Confluent Platform and Confluent Cloud: Arbitrary File Read and Server-Side Request Forgery (SSRF) Vulnerability via unauthorized changes to Kafka Client SASL/OAUTHBEARER configuration
- CONFSA-2025-02: CVE-2025-27818, CVE-2025-27819: Confluent Platform and Confluent Cloud: Certain components vulnerable to deserialization of untrusted data
- Security Release Notes for CFK 2.11.2
- Security Release Notes for CFK 2.11.1
- Security Release Notes for CFK 2.10.2
- Security Release Notes for CFK 2.9.6
- Security Release Notes for CP 7.9.2
- Security Release Notes for CP 7.9.1
- Security Release Notes for CP 7.8.3
- Security Release Notes for CP 7.7.4
- Security Release Notes for CP 7.6.6
- Security Release Notes for CP 7.5.9
- Security Release Notes for CP 7.4.10
- Security Release Notes for CP 7.3.13
- Security Release Notes for CP 7.2.15
- CONFSA-2025-03: CVE-2025-30065 - Self-Managed Connectors with Confluent Platform and Confluent Cloud Managed Connectors Vulnerability: Affected connectors are susceptible to Remote Code Execution (RCE) vulnerability while parsing untrusted Parquet files
- CONFSA-2025-01: CVE-2024-56128 - Confluent Platform Vulnerability: Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation
- Security Release Notes for CFK 2.10.1
- Security Release Notes for CFK 2.9.5
- Security Release Notes for CP 7.8.2
- Security Release Notes for CP 7.8.1
- Security Release Notes for CP 7.7.3
- Security Release Notes for CP 7.6.5
- Security Release Notes for CP 7.5.8
- Security Release Notes for CP 7.4.9
- Security Release Notes for CP 7.3.12
- Security Release Notes for CP 7.2.14