Chapter 5. Fixed issues


The issues fixed in AMQ Streams 2.6 on RHEL.

For details of the issues fixed in Kafka 3.6.0, refer to the Kafka 3.6.0 Release Notes.

Expand
Table 5.1. Fixed issues
Issue NumberDescription

ENTMQST-5575

BackPort fix of ZOOKEEPER-4708 to AMQ Streams

Expand
Table 5.2. Fixed common vulnerabilities and exposures (CVEs)
Issue NumberDescription

ENTMQST-4990

jackson-databind: denial of service via cylic dependencies

ENTMQST-4999

CVE-2023-33201 bouncycastle: potential blind LDAP injection attack using a self-signed certificate

ENTMQST-5023

netty: io.netty:netty-handler: SniHandler 16MB allocation

ENTMQST-5047

CVE-2023-2976 guava: insecure temporary directory creation

ENTMQST-5385

CVE-2023-44981 [2.6] CVE-2023-44981 zookeeper: zookeeper: Authorization Bypass in Apache ZooKeeper

ENTMQST-5139

CVE-2023-20873 spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry

ENTMQST-5160

CVE-2022-46751 apache-ivy: XML External Entity vulnerability

ENTMQST-5173

CVE-2023-41080 tomcat: Open Redirect vulnerability in FORM authentication

ENTMQST-5293

CVE-2023-40167 jetty-http: jetty: Improper validation of HTTP/1 content-length

ENTMQST-5352

CVE-2023-42445 gradle: Possible local text file exfiltration by XML External entity injection

ENTMQST-5353

CVE-2023-44387 gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations

ENTMQST-5398

CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeper

ENTMQST-5427

CVE-2023-31582 jose4j: Insecure iteration count setting

ENTMQST-5437

CVE-2023-5072 in cruise-control

Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat Documentation

Legal Notice

Theme

© 2026 Red Hat
Back to top