Quarkus upstream upgraded Kafka to version 3.7.2 due to fix for CVE-2024-56128 [1], but from product side the latest supported version of Kafka is 3.7.1.
Talked to cescoffi@redhat.com about the situation, we agreed to downgrade to the product supported 3.7.1 as there are no intentions for them to build 3.7.2. The CVE has also not been backported to the product 3.7.1.
- clones
-
QUARKUS-6294 Downgrade Kafka to version 3.7.1
-
- Closed
-
- links to
-
RHSA-2025:154943 Red Hat build of Quarkus 3.15.7 release and security update