confluentinc / confluentinc/confluent-kafka-python

confluent-kafka 2.14.2 / librdkafka 2.14.2 appears to pull vulnerable OpenSSL 3.5.6

Open
#2,282 1 comment 0 reactions 0 assignees View on GitHub
status:planned
Dominant language
Python
Stars
509
Forks
964
Avg merge
2d 2h
Merged PRs (30d)
14

Description

**Title**

confluent-kafka 2.14.2 / librdkafka 2.14.2 appears to pull vulnerable OpenSSL 3.5.6

**Summary**

Our dependency scan reports the following chain:

`confluent-kafka 2.14.2 -> librdkafka 2.14.2 -> OpenSSL 3.5.6`

The reported OpenSSL version is flagged for these CVEs:

`CVE-2026-34180`, `CVE-2026-34181`, `CVE-2026-34183`, `CVE-2026-42764`, `CVE-2026-42766`, `CVE-2026-42767`, `CVE-2026-42769`, `CVE-2026-42770`, `CVE-2026-45445`, `CVE-2026-45446`, `CVE-2026-45447`, `CVE-2026-7383`, `CVE-2026-9076`

We are using:

- `confluent-kafka==2.14.2`
- runtime `librdkafka==2.14.2`

Please confirm whether the distributed `confluent-kafka` artifacts for `2.14.2` bundle or otherwise depend on `OpenSSL 3.5.6`, and if so, please publish a fix by updating to a non-vulnerable OpenSSL version.

**Requested action**

- Confirm the OpenSSL version used by `confluent-kafka 2.14.2` / `librdkafka 2.14.2`
- Clarify affected platforms, wheels, or packages
- Release an updated version with the OpenSSL CVEs remediated

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the dependency scan for confluent-kafka==2.14.2 and tracing its reported librdkafka==2.14.2 to OpenSSL 3.5.6. Check the distributed artifacts across the affected platforms, wheels, or packages; done means confirming the bundled dependency and CVE impact, or documenting that it is not affected and identifying any required release.

Written by the indexing model from the issue text.

Assessment

Tech stack
kafka, python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.