Apache Kafka

tool · Apache Software Foundation

Current status

supported

Supported version lines, end-of-life status, and latest releases for Apache Kafka — derived from official vendor sources, not third-party EOL aggregators.

Apache Kafka is a distributed event streaming platform for high-throughput publish-subscribe, storage, and stream processing workloads.

Security: 12 tracked advisories. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

37

Supported

24

EOL lines

0

Latest stable

11.0.2

2017-11-17

Releases tracked

96

At a glance

Latest release

11.0.2

Line 11.0

Recommended support line

11.0

standard support

Status

STANDARD SUPPORT

Newest supported: 11.0

EOL

Not published

Exact date not officially published

Recommended line: 11.0 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

24 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
11.0
standard supportlow
11.0.22017-11-17Not officially publishedlow
10.2
standard supportlow
10.2.12017-04-26Not officially publishedlow
10.1
standard supportlow
10.1.12016-12-20Not officially publishedlow
10.0
standard supportlow
10.0.12016-08-10Not officially publishedlow
9.0
standard supportlow
9.0.12016-02-19Not officially publishedlow
8.2
standard supportlow
8.2.22015-10-02Not officially publishedlow
4.3
standard supportlow
4.3.12026-06-25Not officially publishedlow
4.2
standard supportlow
4.2.12026-05-30Not officially publishedlow
4.1
standard supportlow
4.1.22026-03-17Not officially publishedlow
4.0
standard supportlow
4.0.22026-03-16Not officially publishedlow
3.9
standard supportlow
3.9.22026-02-21Not officially publishedlow
3.8
standard supportlow
3.8.12024-10-29Not officially publishedlow
3.3
standard supportlow
3.3.2Not officially publishedlow
3.2
standard supportlow
3.2.3Not officially publishedlow
3.1
standard supportlow
3.1.2Not officially publishedlow
3.0
standard supportlow
3.0.2Not officially publishedlow
2.8
standard supportlow
2.8.22022-09-19Not officially publishedlow
2.7
standard supportlow
2.7.22021-11-15Not officially publishedlow
2.6
standard supportlow
2.6.32021-11-15Not officially publishedlow
2.5
standard supportlow
2.5.12020-08-10Not officially publishedlow
2.4
standard supportlow
2.4.12020-03-12Not officially publishedlow
2.0
standard supportlow
2.0.12018-11-09Not officially publishedlow
1.1
standard supportlow
1.1.12018-07-19Not officially publishedlow
1.0
standard supportlow
1.0.2Not officially publishedlow

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 11.0standard support
    standard support
  • 10.2standard support
    standard support
  • 10.1standard support
    standard support
  • 10.0standard support
    standard support
  • 9.0standard support
    standard support
  • 8.2standard support
    standard support
  • 4.3standard support
    standard support
  • 4.2standard support
    standard support
  • 4.1standard support
    standard support
  • 4.0standard support
    standard support
  • 3.9standard support
    standard support
  • 3.8standard support
    standard support
  • 3.3standard support
    standard support
  • 3.2standard support
    standard support
  • 3.1standard support
    standard support
  • 3.0standard support
    standard support

Showing 16 of 24 lines with lifecycle periods. See the directory below for the full list.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2026-41115

    Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API

    Affected:
    >=4.0.0,<=4.3.0
    Source:
    OSV source · Advisory
  • CVE-2026-33557

    Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication

    Affected:
    >=4.1.0,<4.1.2
    Fixed in:
    4.1.2
    Source:
    OSV source · Advisory
  • CVE-2026-33558

    Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

    Affected:
    >=4.0.0-rc3,<3.9.2
    Fixed in:
    3.9.2
    Source:
    OSV source · Advisory
  • CVE-2026-35554

    Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

    Affected:
    >=4.1.0,<4.1.2
    Fixed in:
    4.1.2
    Source:
    OSV source · Advisory
  • CVE-2025-27817

    Apache Kafka Client: Arbitrary file read and SSRF vulnerability

    Affected:
    >=3.1.0,<3.9.1
    Fixed in:
    3.9.1
    Source:
    OSV source · Advisory
  • CVE-2025-27819

    Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration

    Affected:
    >=2.0.0,<=3.3.2
    Source:
    OSV source · Advisory
  • CVE-2025-27818

    Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration

    Affected:
    >=2.3.0,<3.9.1
    Fixed in:
    3.9.1
    Source:
    OSV source · Advisory
  • CVE-2024-56128

    Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption

    Affected:
    >=3.8.0,<3.7.2
    Fixed in:
    3.7.2
    Source:
    OSV source · Advisory
  • CVE-2024-31141

    Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

    Affected:
    >=3.7.0,<=3.7.0
    Source:
    OSV source · Advisory
  • CVE-2024-27309

    Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

    Affected:
    >=3.5.0,<=3.6.1
    Source:
    OSV source · Advisory
  • CVE-2022-34917

    Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers

    Affected:
    >=3.2.0,<3.2.3
    Fixed in:
    3.2.3
    Source:
    OSV source · Advisory
  • CVE-2021-38153
    Affected:
    >=2.8.0-NA,<2.7.2; <2.2.4
    Fixed in:
    2.7.2, 2.2.4
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

11.010.210.110.0
Statusstandard supportstandard supportstandard supportstandard support
Latest11.0.210.2.110.1.110.0.1
Released2017-11-172017-04-262016-12-202016-08-10
EOLNot officially publishedNot officially publishedNot officially publishedNot officially published
Risklowlowlowlow

Recent releases

Latest release date 2017-11-17 · 0 in last 30 days · 1 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Apache Kafka 11.0 (standard support).

Data coverage

Version lines
37
Concrete releases
96
Supported lines
24
EOL lines
0
Lifecycle coverage
24/37
EOL coverage
0/37
Provenance coverage
37/37

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-08-31
Latest source update
2026-08-31

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
11.0
standard supportlow
11.0.22017-11-17Not officially published
10.2
standard supportlow
10.2.12017-04-26Not officially published
10.1
standard supportlow
10.1.12016-12-20Not officially published
10.0
standard supportlow
10.0.12016-08-10Not officially published
9.0
standard supportlow
9.0.12016-02-19Not officially published
8.2
standard supportlow
8.2.22015-10-02Not officially published
4.3
standard supportlow
4.3.12026-06-25Not officially published
4.2
standard supportlow
4.2.12026-05-30Not officially published
4.1
standard supportlow
4.1.22026-03-17Not officially published
4.0
standard supportlow
4.0.22026-03-16Not officially published
3.9
standard supportlow
3.9.22026-02-21Not officially published
3.8
standard supportlow
3.8.12024-10-29Not officially published
3.3
standard supportlow
3.3.2Not officially published
3.2
standard supportlow
3.2.3Not officially published
3.1
standard supportlow
3.1.2Not officially published
3.0
standard supportlow
3.0.2Not officially published
2.8
standard supportlow
2.8.22022-09-19Not officially published
2.7
standard supportlow
2.7.22021-11-15Not officially published
2.6
standard supportlow
2.6.32021-11-15Not officially published
2.5
standard supportlow
2.5.12020-08-10Not officially published
2.4
standard supportlow
2.4.12020-03-12Not officially published
2.0
standard supportlow
2.0.12018-11-09Not officially published
1.1
standard supportlow
1.1.12018-07-19Not officially published
1.0
standard supportlow
1.0.2Not officially published

Archive / no vendor EOL schedule

Lines without a published support schedule from the vendor.

Version lineStatusLatest releaseReleasedEOL
3.7
unknownmedium
3.7.2Not officially published
3.6
unknownmedium
3.6.2Not officially published
3.5
unknownmedium
3.5.8Not officially published
3.4
unknownmedium
3.4.1Not officially published
2.9
unknownmedium
2.9.2Not officially published
2.3
unknownmedium
2.3.1Not officially published
2.2
unknownmedium
2.2.2Not officially published
2.1
unknownmedium
2.1.1Not officially published
0.11
unknownmedium
0.11.0Not officially published
0.10
unknownmedium
0.10.2Not officially published
0.9
unknownmedium
0.9.0Not officially published
0.8
unknownmedium
0.8.2Not officially published
0.7
unknownmedium
0.7.2Not officially published