Visit NES for Apache Kafka Home Page

NES for Apache Kafka Release Notes

Comprehensive release notes and changelog for NES for Apache Kafka, including security patches, bug fixes, and feature updates across all supported versions.

8 Patched Vulnerabilities
VEX Statements

Kafka

3.1.4 (NES) - June 29, 2026

Notes

  • This release originates from the open‑source Kafka project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.

Bug Fixes

This release patches the following:

  • CVE-2025-27818: A Remote Code Execution vulnerability has been identified in the kafka-clients library, which allows an authenticated operator who can set a Kafka client's sasl.jaas.config to point the client at com.sun.security.auth.module.LdapLoginModule
  • CVE-2025-27819: A Remote Code Execution vulnerability has been identified in Apache Kafka, which allows an attacker who can connect to the cluster and holds the AlterConfigs permission on the cluster resource to set a SASL JAAS configuration that names a dangerous login module.
  • CVE-2026-35554: A vulnerability has been identified in the kafka-clients producer, where a race condition in buffer-pool management can cause messages to be silently delivered to the wrong topic.
  • CVE-2026-35558: An Information Exposure vulnerability has been identified in the kafka-clients library, which allows attackers to recover SASL credentials, SCRAM salts and salted passwords, delegation-token HMACs, and broker configuration values from application log files.

Full Version: 3.1.2-kafka-3.1.4

3.1.3 (NES) - November 15, 2025

Notes

  • This release originates from the open‑source Kafka project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.

Bug Fixes

This release patches the following:

  • CVE-2023-25194: potentially enabling remote code execution via unsafe Java deserialization
  • CVE-2024-31141: allows an attacker who can supply untrusted client or connector configuration to abuse built-in ConfigProviders to read arbitrary files or environment variables
  • CVE-2025-27817: allows an attacker who can supply untrusted client or connector configuration to misuse OAuth-related SASL settings to trigger arbitrary file reads or SSRF
  • CVE-2024-56128: potentially enables an attacker with plaintext visibility into a SCRAM authentication exchange to exploit the lack of required nonce verification

Full Version: 3.1.2-kafka-3.1.3