Apache Kafka
tool · Apache Software Foundation
Current status
Supported version lines, end-of-life status, and latest releases for Apache Kafka — derived from official vendor sources, not third-party EOL aggregators.
Apache Kafka is a distributed event streaming platform for high-throughput publish-subscribe, storage, and stream processing workloads.
Security: 12 tracked advisories. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
37
Supported
24
EOL lines
0
Latest stable
11.0.2
2017-11-17
Releases tracked
96
At a glance
Latest release
11.0.2
Line 11.0
Recommended support line
11.0
standard support
Status
STANDARD SUPPORT
Newest supported: 11.0
EOL
Not published
Exact date not officially published
Recommended line: 11.0 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
24 currently supported release lines.
| Version line | Lifecycle | Latest release | Released | EOL | Risk |
|---|---|---|---|---|---|
| 11.0 | standard supportlow | 11.0.2 | 2017-11-17 | Not officially published | low |
| 10.2 | standard supportlow | 10.2.1 | 2017-04-26 | Not officially published | low |
| 10.1 | standard supportlow | 10.1.1 | 2016-12-20 | Not officially published | low |
| 10.0 | standard supportlow | 10.0.1 | 2016-08-10 | Not officially published | low |
| 9.0 | standard supportlow | 9.0.1 | 2016-02-19 | Not officially published | low |
| 8.2 | standard supportlow | 8.2.2 | 2015-10-02 | Not officially published | low |
| 4.3 | standard supportlow | 4.3.1 | 2026-06-25 | Not officially published | low |
| 4.2 | standard supportlow | 4.2.1 | 2026-05-30 | Not officially published | low |
| 4.1 | standard supportlow | 4.1.2 | 2026-03-17 | Not officially published | low |
| 4.0 | standard supportlow | 4.0.2 | 2026-03-16 | Not officially published | low |
| 3.9 | standard supportlow | 3.9.2 | 2026-02-21 | Not officially published | low |
| 3.8 | standard supportlow | 3.8.1 | 2024-10-29 | Not officially published | low |
| 3.3 | standard supportlow | 3.3.2 | — | Not officially published | low |
| 3.2 | standard supportlow | 3.2.3 | — | Not officially published | low |
| 3.1 | standard supportlow | 3.1.2 | — | Not officially published | low |
| 3.0 | standard supportlow | 3.0.2 | — | Not officially published | low |
| 2.8 | standard supportlow | 2.8.2 | 2022-09-19 | Not officially published | low |
| 2.7 | standard supportlow | 2.7.2 | 2021-11-15 | Not officially published | low |
| 2.6 | standard supportlow | 2.6.3 | 2021-11-15 | Not officially published | low |
| 2.5 | standard supportlow | 2.5.1 | 2020-08-10 | Not officially published | low |
| 2.4 | standard supportlow | 2.4.1 | 2020-03-12 | Not officially published | low |
| 2.0 | standard supportlow | 2.0.1 | 2018-11-09 | Not officially published | low |
| 1.1 | standard supportlow | 1.1.1 | 2018-07-19 | Not officially published | low |
| 1.0 | standard supportlow | 1.0.2 | — | Not officially published | low |
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 11.0standard supportstandard support
- 10.2standard supportstandard support
- 10.1standard supportstandard support
- 10.0standard supportstandard support
- 9.0standard supportstandard support
- 8.2standard supportstandard support
- 4.3standard supportstandard support
- 4.2standard supportstandard support
- 4.1standard supportstandard support
- 4.0standard supportstandard support
- 3.9standard supportstandard support
- 3.8standard supportstandard support
- 3.3standard supportstandard support
- 3.2standard supportstandard support
- 3.1standard supportstandard support
- 3.0standard supportstandard support
Showing 16 of 24 lines with lifecycle periods. See the directory below for the full list.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2026-41115
Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
- Affected:
- >=4.0.0,<=4.3.0
- Source:
- OSV source · Advisory
- CVE-2026-33557
Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
- Affected:
- >=4.1.0,<4.1.2
- Fixed in:
- 4.1.2
- Source:
- OSV source · Advisory
- CVE-2026-33558
Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output
- Affected:
- >=4.0.0-rc3,<3.9.2
- Fixed in:
- 3.9.2
- Source:
- OSV source · Advisory
- CVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
- Affected:
- >=4.1.0,<4.1.2
- Fixed in:
- 4.1.2
- Source:
- OSV source · Advisory
- CVE-2025-27817
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
- Affected:
- >=3.1.0,<3.9.1
- Fixed in:
- 3.9.1
- Source:
- OSV source · Advisory
- CVE-2025-27819
Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration
- Affected:
- >=2.0.0,<=3.3.2
- Source:
- OSV source · Advisory
- CVE-2025-27818
Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration
- Affected:
- >=2.3.0,<3.9.1
- Fixed in:
- 3.9.1
- Source:
- OSV source · Advisory
- CVE-2024-56128
Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption
- Affected:
- >=3.8.0,<3.7.2
- Fixed in:
- 3.7.2
- Source:
- OSV source · Advisory
- CVE-2024-31141
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
- Affected:
- >=3.7.0,<=3.7.0
- Source:
- OSV source · Advisory
- CVE-2024-27309
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
- Affected:
- >=3.5.0,<=3.6.1
- Source:
- OSV source · Advisory
- CVE-2022-34917
Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers
- Affected:
- >=3.2.0,<3.2.3
- Fixed in:
- 3.2.3
- Source:
- OSV source · Advisory
- CVE-2021-38153
- Affected:
- >=2.8.0-NA,<2.7.2; <2.2.4
- Fixed in:
- 2.7.2, 2.2.4
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2017-11-17 · 0 in last 30 days · 1 in last 90 days
- —
3.7.2
Line 3.7 · unknown - —
3.7.1
Line 3.7 · unknown - —
3.7.0
Line 3.7 · unknown - —
3.6.2
Line 3.6 · unknown - —
3.6.1
Line 3.6 · unknown - —
3.6.0
Line 3.6 · unknown - —
3.5.8
Line 3.5 · unknown - —
3.5.7
Line 3.5 · unknown - —
3.5.2
Line 3.5 · unknown - —
3.5.1
Line 3.5 · unknown
Should I upgrade?
Current versions are supported
The preferred supported release line is Apache Kafka 11.0 (standard support).
Data coverage
- Version lines
- 37
- Concrete releases
- 96
- Supported lines
- 24
- EOL lines
- 0
- Lifecycle coverage
- 24/37
- EOL coverage
- 0/37
- Provenance coverage
- 37/37
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-08-31
- Latest source update
- 2026-08-31
Sources
First-party and other registered sources contributing release and lifecycle facts.
- Apache Kafka community downloadsfirst party · high
Official source: https://kafka.apache.org/community/downloads/
Last verified 2026-08-31
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-08-31
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-08-31
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-08-31
- Apache Kafka GitHub tagsfirst party
Official source: https://api.github.com/repos/apache/kafka/tags
Last checked 2026-08-31
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 11.0 | standard supportlow | 11.0.2 | 2017-11-17 | Not officially published |
| 10.2 | standard supportlow | 10.2.1 | 2017-04-26 | Not officially published |
| 10.1 | standard supportlow | 10.1.1 | 2016-12-20 | Not officially published |
| 10.0 | standard supportlow | 10.0.1 | 2016-08-10 | Not officially published |
| 9.0 | standard supportlow | 9.0.1 | 2016-02-19 | Not officially published |
| 8.2 | standard supportlow | 8.2.2 | 2015-10-02 | Not officially published |
| 4.3 | standard supportlow | 4.3.1 | 2026-06-25 | Not officially published |
| 4.2 | standard supportlow | 4.2.1 | 2026-05-30 | Not officially published |
| 4.1 | standard supportlow | 4.1.2 | 2026-03-17 | Not officially published |
| 4.0 | standard supportlow | 4.0.2 | 2026-03-16 | Not officially published |
| 3.9 | standard supportlow | 3.9.2 | 2026-02-21 | Not officially published |
| 3.8 | standard supportlow | 3.8.1 | 2024-10-29 | Not officially published |
| 3.3 | standard supportlow | 3.3.2 | — | Not officially published |
| 3.2 | standard supportlow | 3.2.3 | — | Not officially published |
| 3.1 | standard supportlow | 3.1.2 | — | Not officially published |
| 3.0 | standard supportlow | 3.0.2 | — | Not officially published |
| 2.8 | standard supportlow | 2.8.2 | 2022-09-19 | Not officially published |
| 2.7 | standard supportlow | 2.7.2 | 2021-11-15 | Not officially published |
| 2.6 | standard supportlow | 2.6.3 | 2021-11-15 | Not officially published |
| 2.5 | standard supportlow | 2.5.1 | 2020-08-10 | Not officially published |
| 2.4 | standard supportlow | 2.4.1 | 2020-03-12 | Not officially published |
| 2.0 | standard supportlow | 2.0.1 | 2018-11-09 | Not officially published |
| 1.1 | standard supportlow | 1.1.1 | 2018-07-19 | Not officially published |
| 1.0 | standard supportlow | 1.0.2 | — | Not officially published |
Archive / no vendor EOL schedule
Lines without a published support schedule from the vendor.
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 3.7 | unknownmedium | 3.7.2 | — | Not officially published |
| 3.6 | unknownmedium | 3.6.2 | — | Not officially published |
| 3.5 | unknownmedium | 3.5.8 | — | Not officially published |
| 3.4 | unknownmedium | 3.4.1 | — | Not officially published |
| 2.9 | unknownmedium | 2.9.2 | — | Not officially published |
| 2.3 | unknownmedium | 2.3.1 | — | Not officially published |
| 2.2 | unknownmedium | 2.2.2 | — | Not officially published |
| 2.1 | unknownmedium | 2.1.1 | — | Not officially published |
| 0.11 | unknownmedium | 0.11.0 | — | Not officially published |
| 0.10 | unknownmedium | 0.10.2 | — | Not officially published |
| 0.9 | unknownmedium | 0.9.0 | — | Not officially published |
| 0.8 | unknownmedium | 0.8.2 | — | Not officially published |
| 0.7 | unknownmedium | 0.7.2 | — | Not officially published |
