# CVE‑2025‑12183 this vulnerability compression.type for topic and producer

**URL:** <https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200>\
**Category:** Ops\
**Created:** [24 December 2025 10:38 UTC](https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200 "2025-12-24T10:38:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![asif123](https://avatars.discourse-cdn.com/v4/letter/a/eada6e/32.png) [@asif123](https://forum.confluent.io/u/asif123)\
**Post date:** [24 December 2025 10:38 UTC](https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200/1 "2025-12-24T10:38:22Z")

</div>

Please assist to check the compression.type configuration for Kafka Broker and also at topic level to assess if CVE‐2025‐12183 is affecting applications.

This is with regards to the latest vulnerability found related to Kafka:

[Sonatype CVE Feed - CVE‐2025‐12183](https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-12183)

---

<div class="post-metadata">

**Author:** ![dtroiano](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/dtroiano/32/1961_2.png) [@dtroiano](https://forum.confluent.io/u/dtroiano)\
**Post date:** [5 January 2026 15:49 UTC](https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200/6 "2026-01-05T15:49:08Z")

</div>

The `lz4-java` dependency was upgraded from 1.8.0 to 1.10.1 as part of the Apache Kafka 4.1 release and also backported to 3.9.2 ([JIRA](https://issues.apache.org/jira/browse/KAFKA-19951), [GitHub](https://github.com/apache/kafka/commit/2f71a535af2e90d9dacc4faee92d89b9bfd829d8)).
