Upgrade kafka client to at-least 3.9.1 to remediate CVE-2025-27817
envgap__openzipkin__zipkin-3805
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
beb87edf95afd29b3691101f9e984a53e25f9255- Manifest
zipkin-collector/kafka/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
openzipkin/zipkin #3805 · read the original issue
In our vulnerability scans zipkin is getting flagged for CVE-2025-27817 due to the presence of kafka client 3.6.0. Can the kafka client to be upgraded to atleast 3.9.1 to remediate this?
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]