Skip to content

KAFKA-20344: Upgrade Jetty to 12.0.34 (4.1)#21940

Merged
FrankYang0529 merged 1 commit intoapache:4.1from
mingyen066:kafka-20344-upgrade-jetty-12.0.34-4.1
Apr 4, 2026
Merged

KAFKA-20344: Upgrade Jetty to 12.0.34 (4.1)#21940
FrankYang0529 merged 1 commit intoapache:4.1from
mingyen066:kafka-20344-upgrade-jetty-12.0.34-4.1

Conversation

@mingyen066
Copy link
Copy Markdown
Collaborator

@mingyen066 mingyen066 commented Apr 2, 2026

Cherry-pick of #21939 to 4.1.

Upgrade Jetty from 12.0.25 to 12.0.34. Jetty 12.0.34 has removed all
dependencies on the SLF4J 2.x API, resolving the previous
incompatibility with Kafka's SLF4J 1.7.x usage. This also fixes
CVE-2025-11143 in jetty-http.

Reviewers: Chia-Ping Tsai chia7712@gmail.com, PoAn Yang
payang@apache.org

FrankYang0529 pushed a commit that referenced this pull request Apr 3, 2026
Upgrade Jetty from 12.0.25 to 12.0.34.

Jetty 12.0.34 has removed all dependencies on the SLF4J 2.x API,
resolving the previous incompatibility with Kafka's SLF4J 1.7.x usage.
This also fixes CVE-2025-11143 in jetty-http.

This can be cherry-picked to 4.3 and 4.2. A separate PR for 4.1: #21940.

Reviewers: PoAn Yang <payang@apache.org>
FrankYang0529 pushed a commit to FrankYang0529/kafka that referenced this pull request Apr 3, 2026
Upgrade Jetty from 12.0.25 to 12.0.34.

Jetty 12.0.34 has removed all dependencies on the SLF4J 2.x API,
resolving the previous incompatibility with Kafka's SLF4J 1.7.x usage.
This also fixes CVE-2025-11143 in jetty-http.

This can be cherry-picked to 4.3 and 4.2. A separate PR for 4.1: apache#21940.

Reviewers: PoAn Yang <payang@apache.org>
(cherry picked from commit 55a7c2f)
FrankYang0529 pushed a commit to FrankYang0529/kafka that referenced this pull request Apr 3, 2026
Upgrade Jetty from 12.0.25 to 12.0.34.

Jetty 12.0.34 has removed all dependencies on the SLF4J 2.x API,
resolving the previous incompatibility with Kafka's SLF4J 1.7.x usage.
This also fixes CVE-2025-11143 in jetty-http.

This can be cherry-picked to 4.3 and 4.2. A separate PR for 4.1: apache#21940.

Reviewers: PoAn Yang <payang@apache.org>
(cherry picked from commit 55a7c2f)
@chia7712
Copy link
Copy Markdown
Member

chia7712 commented Apr 3, 2026

I have cherry-picked #20649 to 4.1. @mingyen066 would you mind updating PR?

@chia7712 chia7712 force-pushed the kafka-20344-upgrade-jetty-12.0.34-4.1 branch from 2dd4fd6 to 2fd74a2 Compare April 3, 2026 13:30
@FrankYang0529 FrankYang0529 merged commit a4ce516 into apache:4.1 Apr 4, 2026
20 checks passed
nileshkumar3 pushed a commit to nileshkumar3/kafka that referenced this pull request Apr 15, 2026
Upgrade Jetty from 12.0.25 to 12.0.34.

Jetty 12.0.34 has removed all dependencies on the SLF4J 2.x API,
resolving the previous incompatibility with Kafka's SLF4J 1.7.x usage.
This also fixes CVE-2025-11143 in jetty-http.

This can be cherry-picked to 4.3 and 4.2. A separate PR for 4.1: apache#21940.

Reviewers: PoAn Yang <payang@apache.org>
mimaison pushed a commit that referenced this pull request Apr 17, 2026
Cherry-pick of #21939 to 4.1.

Upgrade Jetty from 12.0.25 to 12.0.34. Jetty 12.0.34 has removed all
dependencies on the SLF4J 2.x API, resolving the previous
incompatibility with Kafka's SLF4J 1.7.x usage. This also fixes
CVE-2025-11143 in jetty-http.

Reviewers: Chia-Ping Tsai <chia7712@gmail.com>, PoAn Yang
 <payang@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants