// OSSeva Blog
SecurityApache Flink Vulnerabilities by Version: CVEs for Flink 1.x, 1.20 LTS and 2.x
The short answer
The Flink community supports the current and previous minor release, today 2.3 and 2.2, and labels 1.20 as its long-term support line. NVD has only four CVE records for Flink itself and three for its subprojects, but the one from 2026 is serious. CVE-2026-35194 lets a user who can submit SQL run code on the TaskManagers, and it reaches every release from 1.15.0. It is fixed in 1.20.4, 2.0.2, 2.1.2 and 2.2.1, and 2.3.0, released after those fixes, is outside the affected range. Flink 1.19 and older have no fix: 1.19.3 from July 2025 was the last 1.19 release, and the lines before it ended earlier still.
One older Flink CVE is in CISA's Known Exploited Vulnerabilities catalogue: CVE-2020-17519, a file read through the JobManager REST API in 1.11.0 to 1.11.2, added on 23 May 2024. Clusters that stopped at 1.11.2 still carry it.
Flink release lines and their CVEs
Release dates are from the Flink download page, which also states the update policy. The page labels 1.20 LTS but gives no end date. Each row lists the Flink CVEs from the Apache advisories whose ranges include the line and that have no fix in its latest release.
| Line | Upstream status | Latest release | CVEs with no fix on this line | Upstream fix on this line |
|---|---|---|---|---|
| 2.3 | Current minor, supported | 2.3.0, 25 June 2026 | None | Not applicable |
| 2.2 | Previous minor, supported | 2.2.1, 15 May 2026 | None | 2.2.1 for CVE-2026-35194 |
| 2.1 | Out of the support window since 2.3.0 | 2.1.3, 14 June 2026 | None | 2.1.2 for CVE-2026-35194 |
| 2.0 | Out of the support window since 2.2.0 | 2.0.2, 11 May 2026 | None | 2.0.2 for CVE-2026-35194 |
| 1.20 LTS | Labelled LTS, no published end date | 1.20.5, 3 June 2026 | None | 1.20.4 for CVE-2026-35194 |
| 1.19 | Out of support | 1.19.3, 10 July 2025 | CVE-2026-35194 | No upstream fix on this line |
| 1.17 and 1.18 | Out of support | 1.18.1, 19 January 2024; 1.17.2, 29 November 2023 | CVE-2026-35194, through JSON functions and LIKE with ESCAPE | No upstream fix on these lines |
| 1.15 and 1.16 | Out of support | 1.16.3, 20 November 2023; 1.15.4, 15 March 2023 | CVE-2026-35194, through JSON functions | No upstream fix on these lines |
| 1.12 to 1.14 | Out of support | 1.14.6, 28 September 2022; 1.13.6; 1.12.7 | None from the Flink advisories | Not applicable |
| 1.11 and older | Out of support | 1.11.6, 16 December 2021; 1.10.3 | CVE-2020-17518 and CVE-2020-17519 on 1.11.2 and older; CVE-2020-1960 on 1.10.0 and older | 1.11.3 for the two REST API CVEs; 1.9.3 and 1.10.1 for CVE-2020-1960 |
Since March 2023 the update policy promises one final bugfix release for a minor line when it leaves the support window, and nothing after that, though the community says it is open to discussing releases for older versions on the dev list. FLIP-458, the proposal behind the 1.20 LTS line, describes two years of bug fixes and security updates, but treat that as a plan rather than a commitment. For dates on every line, see the Apache Flink end-of-life chart.
Notable Flink CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. For CVE-2025-62228, Apache as the CNA gives 5.1 under CVSS 4.0, well below NVD's 8.8.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2025-62228 | Flink CDC: SQL injection through crafted database or table names | 8.8 (NVD) | Flink CDC 3.0.0 to 3.4.0 | Flink CDC 3.5.0 |
| CVE-2026-35194 | SQL code generation interpolates user strings into generated Java without escaping, so a user who can submit queries runs code on TaskManagers | 8.1 (CISA-ADP) | 1.15.0 to 1.20.3; 2.0.0 to 2.0.1; 2.1.0 to 2.1.1; 2.2.0 | 1.20.4, 2.0.2, 2.1.2, 2.2.1 |
| CVE-2020-17518 | A REST handler writes uploaded files to any location through a modified HTTP header | 7.5 (NVD) | 1.5.1 to 1.11.2 | 1.11.3, 1.12.0 |
| CVE-2020-17519 | The JobManager REST interface reads any file the JobManager process can access; in CISA's KEV catalogue | 7.5 (NVD) | 1.11.0 to 1.11.2 | 1.11.3, 1.12.0 |
| CVE-2026-40564 | Kubernetes Operator: an unvalidated FlinkSessionJob jarURI lets a user who can create the resource read operator pod files and reach internal addresses | 6.5 (NVD) | Kubernetes Operator 1.3.0 before 1.15.0 | Kubernetes Operator 1.15.0 |
| CVE-2023-41834 | Stateful Functions: CRLF sequences in HTTP requests allow header injection and response splitting | 6.1 (NVD) | Stateful Functions 3.1.0 to 3.2.0 | Stateful Functions 3.3.0 |
| CVE-2020-1960 | With a JMX reporter port configured, a local attacker can rebind the JMX RMI registry and intercept JMX connections | 4.7 (NVD) | 1.1.0 to 1.10.0 | 1.9.3, 1.10.1 |
Flink's security model explains why the list is short. The project treats anyone who can submit a JAR, DataStream program or UDF as fully trusted, because Flink runs that code unconditionally, and it reports code execution through those paths as out of scope. SQL is the exception: the Flink security page puts SQL Gateway submissions inside the security boundary, and CVE-2026-35194 is the case where an SQL query escapes it. It matters most where people who should not run arbitrary code can submit SQL, such as a shared SQL Gateway or a platform that runs SQL on behalf of its users. TLS, REST API authentication and SQL Gateway authentication are all off by default, so a reachable REST port was all the 2020 REST CVEs needed.
The ZooKeeper client Flink uses for high availability is shaded into every release as flink-shaded-zookeeper. Flink 1.15 and 1.16 build against ZooKeeper 3.5.9, 1.17 to 1.20.5 against 3.7.1 and 2.3.0 against 3.7.2. ZooKeeper 3.7.1 is inside the range of CVE-2023-44981, a SASL quorum authentication bypass scored 9.1 by NVD. That flaw is in quorum peer authentication, so it matters most where the ensemble runs this code, for example one started with Flink's start-zookeeper-quorum.sh script, and elsewhere it shows up as a scanner finding against the shaded jar.
What each line gets
Flink 2.2 and 2.3
These are the supported minor lines and both carry every fix above. 2.3.0 also moves the shaded ZooKeeper to 3.7.2, which is outside the range of CVE-2023-44981.
Flink 1.20 LTS
1.20.4 fixed CVE-2026-35194, and 1.20.5 from June 2026 is the latest release. It still shades ZooKeeper 3.7.1. As the last 1.x line, 1.20 is the bridge to 2.x: it restores savepoints from older 1.x releases and warns about the APIs 2.0 removed.
Flink 2.0 and 2.1
Both have the CVE-2026-35194 fix in 2.0.2 and 2.1.2, but neither is inside the support window any longer, so the next fix will come only on 2.2 and later.
Flink 1.15 to 1.19
None of these lines has a fix for CVE-2026-35194. The JSON functions path reaches 1.15 and 1.16, and the LIKE with ESCAPE path also reaches 1.17 to 1.19. The upgrade within 1.x is to 1.20.5, which keeps the 1.x APIs; the move to 2.x is a port of job code; see upgrading Flink 1.18, 1.19 and 1.20 to Flink 2.x.
Flink 1.14 and older
Releases from 1.12.0 on have the 2020 REST API fixes. Releases from 1.11.0 to 1.11.2 carry CVE-2020-17519, the KEV-listed file read, and 1.5.1 to 1.11.2 carry the file write in CVE-2020-17518.
What to do on each line
- 2.x. Take 2.2.1 or 2.3.0, and plan to follow the support window as new minors ship.
- 1.20. Take 1.20.5, and use the LTS period to port jobs to 2.x.
- 1.15 to 1.19. Move to 1.20.5, or take patched builds from a supplier that backports fixes. Until then, do not let untrusted users submit SQL, put authentication in front of the REST API and SQL Gateway, and keep JobManager and TaskManager ports off untrusted networks, as the Flink security page requires for every deployment.
- 1.11 and older. Upgrade, at minimum past 1.11.3, and treat any 1.11.0 to 1.11.2 JobManager with a reachable REST port as exposed to a known-exploited flaw.
- Kubernetes Operator and Flink CDC. Run Operator 1.15.0 or later and CDC 3.5.0 or later.
For the ZooKeeper side of Flink high availability, see Flink HA: ZooKeeper vs Kubernetes HA services.
Where OSSeva fits
OSSeva ships patched, signed builds of Apache Flink 1.15 to 1.19 with the savepoint format unchanged, a patched flink-shaded-zookeeper in every build and transitive dependency patching for Netty, Jackson and logging, delivered as Maven artifacts, Docker images and tarballs. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a high availability review, a ZooKeeper ensemble ACL, SASL and exposure audit, an inventory of removed 2.x APIs used by each job and an upgrade plan to 1.20 LTS or 2.x with savepoint compatibility checks, and Operate adds 24/7 checkpoint, backpressure and JobManager failover monitoring with a 15-minute P1 response, a named senior Flink engineer and a staged 2.x migration, job by job. See Apache Flink support and Flink extended support.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.