confluentinc / confluentinc/confluent-kafka-python
confluent-kafka 2.14.2 / librdkafka 2.14.2 appears to pull vulnerable OpenSSL 3.5.6
- Dominant language
- Python
- Stars
- 509
- Forks
- 964
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 14
Description
**Title**
confluent-kafka 2.14.2 / librdkafka 2.14.2 appears to pull vulnerable OpenSSL 3.5.6
**Summary**
Our dependency scan reports the following chain:
`confluent-kafka 2.14.2 -> librdkafka 2.14.2 -> OpenSSL 3.5.6`
The reported OpenSSL version is flagged for these CVEs:
`CVE-2026-34180`, `CVE-2026-34181`, `CVE-2026-34183`, `CVE-2026-42764`, `CVE-2026-42766`, `CVE-2026-42767`, `CVE-2026-42769`, `CVE-2026-42770`, `CVE-2026-45445`, `CVE-2026-45446`, `CVE-2026-45447`, `CVE-2026-7383`, `CVE-2026-9076`
We are using:
- `confluent-kafka==2.14.2`
- runtime `librdkafka==2.14.2`
Please confirm whether the distributed `confluent-kafka` artifacts for `2.14.2` bundle or otherwise depend on `OpenSSL 3.5.6`, and if so, please publish a fix by updating to a non-vulnerable OpenSSL version.
**Requested action**
- Confirm the OpenSSL version used by `confluent-kafka 2.14.2` / `librdkafka 2.14.2`
- Clarify affected platforms, wheels, or packages
- Release an updated version with the OpenSSL CVEs remediated
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reproducing the dependency scan for confluent-kafka==2.14.2 and tracing its reported librdkafka==2.14.2 to OpenSSL 3.5.6. Check the distributed artifacts across the affected platforms, wheels, or packages; done means confirming the bundled dependency and CVE impact, or documenting that it is not affected and identifying any required release.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kafka, python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100