Release Notes - Kafka - Version 4.2.2
Below is a summary of the JIRA issues addressed in the 4.2.2
release of Kafka. For full documentation of the release, a guide
to get started, and information about the project, see the
Kafka project site.
Note about upgrades: Please carefully review the
upgrade documentation for this release thoroughly before upgrading
your cluster. The upgrade notes discuss any critical information about
incompatibilities and breaking changes, performance changes, and any
other changes that might impact your production deployment of Kafka.
The documentation for the most recent release can be found at
https://kafka.apache.org/documentation.html.
Bug
[KAFKA-14597] - [Streams] record-e2e-latency-max is not reporting correct metrics
[KAFKA-20187] - AsyncKafkaConsumer does not clear endOffsetRequested flag on failed LIST_OFFSETS calls
[KAFKA-20253] - High CPU loop on consumer after failed re-authentication
[KAFKA-20464] - Linking stores using ConnectedStoreProvider causes corrupt topology
[KAFKA-20533] - ShareFetch returns UNKNOWN_SERVER_ERROR when topic is deleted during active share consumption
[KAFKA-20570] - Catch RuntimeException in ConsumerProtocol deserialization in group coordinator
[KAFKA-20605] - upgrade gradle action to enable the CI
[KAFKA-20634] - Spurious HighWatermarkUpdate failed errors in the group coordinator after partition leadership change
[KAFKA-20635] - Spurious "Writing records..." failed errors in the group coordinator after partition leadership change
[KAFKA-20640] - Consumer group accepts new classic members when migration policy is disabled
[KAFKA-20662] - Proper error code for malformed request during online migration
[KAFKA-20673] - AdminClient partition-leader APIs hang when a cached leader has left the cluster
[KAFKA-20685] - EOS: checkpoint file written at restoration completion persists through RUNNING, state wipe is skipped after unclean crash
[KAFKA-20699] - TopologyTestDriver.getStateStore corrupts the task's record context
[KAFKA-20711] - Streams task restore-remaining-records metric never reaches 0
[KAFKA-20726] - Don't reuse the BufferSupplier in kraft state machine
[KAFKA-20746] - NPE in MetadataCache#toCluster
[KAFKA-20767] - [CVE-2026-54513] , [CVE-2026-54512] [jackson-databind] [2.21.2]
[KAFKA-20769] - ListDeserializer can silently deserialize a corrupted entry when the input is truncated mid-entry
[KAFKA-20773] - [CVE-2026-54515][jackson-databind]
[KAFKA-20782] - IQ returns incorrect metadata when Streams protocol and N threads
[KAFKA-20791] - Bump log4j to 2.25.5
[KAFKA-20815] - Security : [jline-remote-telnet] [3.30.4]
[KAFKA-20840] - Bump jetty to 12.0.37
[KAFKA-20845] - Consumer group downgrades can leave group in invalid state when classic group metadata is very large
[KAFKA-20861] - Kafka Streams should handle corrupted assignment pro-actively
[KAFKA-20873] - KafkaStreams.removeStreamThread can deadlock with a concurrent REPLACE_THREAD uncaught-exception handler
[KAFKA-20885] - Incorrect IQ metadata in "streams" protocol
[KAFKA-20899] - StickyTaskAssignor not sticky for standby tasks ("streams" protocol)
[KAFKA-21004] - [CVE-2026-68497][jackson-databind]
[KAFKA-21096] - SharePartition instances pending cleanup even when fenced
Task
[KAFKA-20660] - Add guardrail to detect use of legacy ConsumerRecords constructor via nextOffsets()
[KAFKA-20936] - Bump lz4 to 1.11.2