Summary
Our dependency scan reports the following dependency chain:
confluent-kafka 2.14.2 → librdkafka 2.14.2 → Source/autoconf builds: libcurl 8.20.0, vcpkg-based builds: libcurl 8.19.0
The bundled curl/libcurl component is flagged for these CVEs:
CVE-2026-10536, CVE-2026-11564, CVE-2026-11856, CVE-2026-8924,
CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-8458
We are using:
- confluent-kafka==2.14.2
- librdkafka==2.14.2
Please confirm whether the distributed confluent-kafka/librdkafka artifacts bundle or depend on this curl/libcurl version.
Requested action
- Provide the minimum fixed version or recommended mitigation.
References
Summary
Our dependency scan reports the following dependency chain:
confluent-kafka 2.14.2 → librdkafka 2.14.2 → Source/autoconf builds: libcurl 8.20.0, vcpkg-based builds: libcurl 8.19.0
The bundled curl/libcurl component is flagged for these CVEs:
CVE-2026-10536, CVE-2026-11564, CVE-2026-11856, CVE-2026-8924,
CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-8458
We are using:
Please confirm whether the distributed confluent-kafka/librdkafka artifacts bundle or depend on this curl/libcurl version.
Requested action
References