Back to blog

// OSSeva Blog

Security

Apache Pulsar Vulnerabilities by Version: CVEs for Pulsar 2.x, 3.x, 4.x and 5.0

Matt Reynolds9 min read

The short answer

Pulsar 5.0.0, the first release of the next LTS line, came out on 5 October 2026, the same day as 4.0.14. The release policy gives 5.0 active support until 5 October 2028 and security support until 5 October 2029, and gives 4.0 LTS active support until 21 October 2026 and security support until 21 October 2027. Every other line is out of support: 4.2 ended on 24 September 2026, 4.1 on 8 March 2026, and 3.0 LTS lost security support on 2 May 2026. The Pulsar security page lists 20 CVEs, the most recent from April 2025, plus a set of expedited releases for the Avro flaw CVE-2024-47561. Fixes have reached some lines after their support ended, but 2.x, 3.1 and 3.2 are each missing at least two.

Pulsar release lines and their CVEs

Support dates are from the Pulsar release policy page. Each row lists the CVEs from the Pulsar security page, plus CVE-2024-47561, that name the line and have no fix on it.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
5.0 LTSSupported; active to 5 October 2028, security to 5 October 20295.0.0, 5 October 2026NoneNot applicable
4.2Support ended 24 September 20264.2.5NoneNot applicable
4.1Support ended 8 March 20264.1.3NoneNot applicable
4.0 LTSActive to 21 October 2026, security to 21 October 20274.0.14, 5 October 2026None; CVE-2025-30677 affects 4.0.0 to 4.0.34.0.4
3.3Support ended 5 December 20243.3.9None; CVE-2024-47561 and CVE-2025-30677 got ad hoc fixes3.3.2 and 3.3.6
3.2Support ended 5 August 20243.2.4CVE-2024-47561, CVE-2025-30677No upstream fix on this line
3.1Support ended 10 February 20243.1.3CVE-2024-29834, CVE-2024-47561, CVE-2025-30677No upstream fix on this line
3.0 LTSSecurity support ended 2 May 20263.0.17None so far3.0.3, 3.0.4, 3.0.7 and 3.0.11 carry the 2024 and 2025 fixes
2.11Support ended 11 January 20242.11.4CVE-2024-29834, CVE-2024-47561, CVE-2025-30677No upstream fix on this line; 2.11.4 has the earlier 2024 fixes
2.10Support ended 18 April 20232.10.6CVE-2023-51437, CVE-2024-29834, CVE-2024-47561, CVE-2025-30677No upstream fix on this line; 2.10.6 has the earlier 2024 fixes
2.9 and older2.9 ended 20 December 2022, 2.8 on 15 June 20222.9.5; 2.8.4CVE-2024-27135, CVE-2024-27317, CVE-2024-27894, CVE-2022-34321, CVE-2024-28098, CVE-2023-51437, CVE-2024-29834 and the later ones; 2.8 and 2.9 also CVE-2023-37544No upstream fix on these lines

The release policy says the project does not announce end of support separately, and may make ad hoc releases for older lines on a best-effort basis when a CVE is serious enough. That is how 2.10.6 and 2.11.4 came out in March 2024, eleven and two months after those lines ended, and how 3.3 got 3.3.2 and 3.3.6. None of that is guaranteed for the next CVE. For dates on every line, see the Apache Pulsar end-of-life chart.

Notable Pulsar CVEs by release line

CVSS is NVD's own score where NVD has scored the record. For CVE-2024-47561, which is in the Avro Java SDK that Pulsar bundles, NVD has no score of its own and the figure is the CVSS 3.1 score CISA-ADP added. Apache's own scores, as the CNA, often differ from NVD's: it scores the Function Worker CVEs 8.4 to 8.5 where NVD gives 9.9 for two of them. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2024-27135An authenticated user can run arbitrary Java code on the Function Worker, outside the function sandbox; also brokers with functionsWorkerEnabled=true9.9 (NVD)2.4.0 to 2.10.5, 2.11.0 to 2.11.3, 3.0.0 to 3.0.2, 3.1.0 to 3.1.2, 3.2.02.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1
CVE-2024-27317A crafted jar or nar uploaded to the Function Worker writes files outside the extraction directory9.9 (NVD)Same as CVE-2024-271352.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1
CVE-2021-22160JWT authentication accepts tokens with the "none" algorithm, so anyone can connect as any user9.8 (NVD)Before 2.7.12.7.1
CVE-2024-27894Functions created from a URL let an authenticated user read local files and use the worker as an HTTP proxy8.8 (NVD)Same as CVE-2024-271352.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1
CVE-2023-30429Behind a proxy using mTLS, the Function Worker authorizes requests with the proxy's role instead of the client's8.8 (NVD)Before 2.10.4; 2.11.02.10.4, 2.11.1
CVE-2022-34321The proxy's /proxy-stats endpoint needs no authentication and can change proxied connections' logging level8.2 (NVD)2.6.0 to 2.10.5, 2.11.0 to 2.11.2, 3.0.0 to 3.0.1, 3.1.02.10.6, 2.11.3, 3.0.2, 3.1.1
CVE-2023-30428A custom header on the broker's REST producer lets an authenticated user produce to any topic with the broker's admin role8.1 (NVD)2.9.0 to 2.9.5, 2.10.0 to 2.10.3, 2.11.02.10.4, 2.11.1
CVE-2023-37544The WebSocket proxy's /pingpong endpoint accepts unauthenticated connections7.5 (NVD)2.8.x, 2.9.x, 2.10.0 to 2.10.4, 2.11.0 to 2.11.1, 3.0.02.10.5, 2.11.2, 3.0.1
CVE-2023-51437A timing side channel lets an attacker forge a SASL role token that passes signature checks7.4 (NVD)Through 2.10.5, 2.11.0 to 2.11.2, 3.0.0 to 3.0.1, 3.1.02.11.3, 3.0.2, 3.1.1
CVE-2024-47561Schema parsing in the bundled Avro Java SDK before 1.11.4 allows code execution7.3 (CISA-ADP)Pulsar releases with Avro 1.11.3 or older, in servers and the Java client3.0.7, 3.3.2, 4.0.0
CVE-2025-30677The Kafka source, sink and Kafka Connect adaptor connectors log Kafka credentials in plain text6.5 (NVD)All versions before 3.0.11, 3.3.6 and 4.0.43.0.11, 3.3.6, 4.0.4
CVE-2024-29834Users with only produce or consume permission can unload partitioned topics, trigger compaction and change subscription properties6.4 (NVD)2.7.1 to 2.10.6, 2.11.0 to 2.11.4, 3.0.0 to 3.0.3, 3.1.0 to 3.1.3, 3.2.0 to 3.2.13.0.4, 3.2.2
CVE-2024-28098Users with only produce or consume permission can change topic-level retention, TTL and offload policies5.4 (NVD)2.7.1 to 2.10.5, 2.11.0 to 2.11.3, 3.0.0 to 3.0.2, 3.1.0 to 3.1.2, 3.2.02.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1

Most of this list comes down to two features. The first is Pulsar Functions: CVE-2024-27135, CVE-2024-27317, CVE-2024-27894, CVE-2023-30429 and CVE-2023-37579 all need the Function Worker, either as a separate service or inside the broker with functionsWorkerEnabled=true, and a cluster that does not run Functions is not exposed to them. The second is multi-tenant authorization: CVE-2024-28098, CVE-2024-29834 and CVE-2023-30428 let a tenant with ordinary produce or consume rights act beyond them, which matters most where several teams share one cluster. CVE-2024-47561 is different, because Avro is in the Java client as well as the brokers, so applications need the newer client too.

What each line gets

Pulsar 5.0 LTS

5.0.0 is the newest release and the start of the next LTS line. The policy supports live upgrade and downgrade from one LTS to the next, so 4.0 to 5.0 is the planned path, while 3.x to 5.0 is not supported in one step.

Pulsar 4.0 LTS

4.0.14 carries every fix above that applies to 4.0, and 4.0.0 already shipped Avro 1.11.4. Active support ends on 21 October 2026, after which 4.0 gets security fixes only until 21 October 2027. See Apache Pulsar 4.0 end of life.

Pulsar 4.1 and 4.2

Feature releases get six months of support. No advisory names 4.1 or 4.2, but neither line will get the fix for the next CVE, so the move from either is to 5.0 or back onto the 4.0 LTS line.

Pulsar 3.3, 3.2 and 3.1

These feature lines ended in 2024. 3.3 received ad hoc releases with the fixes for CVE-2024-47561 and CVE-2025-30677, so 3.3.9 has every fix above. 3.2.4 and 3.1.3 do not: both still bundle the vulnerable Avro, and 3.1 also has no fix for CVE-2024-29834, whose advisory sends 3.1 users to 3.2.2. The policy allows live upgrade from 3.2 to 4.0.

Pulsar 3.0 LTS

3.0 lost security support on 2 May 2026. Its last release, 3.0.17, carries every fix above, so the reason to move is that the next CVE will not reach it. The live upgrade path is 3.0 to 4.0; see the Pulsar 3.0 to 4.0 upgrade guide and Apache Pulsar 3.0 end of life.

Pulsar 2.10, 2.11 and older

2.10.6 and 2.11.4 carry the March 2024 Function Worker and proxy fixes, but not the April 2024 fix for CVE-2024-29834, nor the Avro or Kafka connector fixes. The CVE-2023-51437 advisory, for the SASL token forgery, names no 2.10 fix and sends 2.10 users to 2.11.3 or later. 2.9 and older have none of the 2024 fixes, including the Function Worker remote code execution, and 2.8 and 2.9 also lack the WebSocket proxy fix. Before 3.0 the policy requires upgrading one feature version at a time, so getting from 2.10 to 3.0 means passing through 2.11. 2.x clusters also run on ZooKeeper; see ZooKeeper for Pulsar.

What to do on each line

  • 5.0 and 4.0. Take each patch release, and plan the move from 4.0 to 5.0 before 4.0 security support ends in October 2027.
  • 4.1 and 4.2. Move to 5.0.
  • 3.x. Move to 4.0 with a live upgrade, then to 5.0. The policy's own examples include 3.0 to 4.0 and 3.2 to 4.0.
  • 2.x. Upgrade feature by feature to 3.0, or take patched builds from a supplier that backports fixes. Until then, disable the Function Worker if you do not use Functions, keep the proxy and its admin endpoints off untrusted networks, and review which roles hold produce and consume rights across tenants.
  • Every line. Upgrade the Pulsar Java client in applications to 3.0.7, 3.3.2, 4.0.0 or later for CVE-2024-47561, whatever version the brokers run.

Where OSSeva fits

OSSeva ships CVE-patched, GPG-signed Pulsar builds for 2.10.x, 2.11.x, 3.0.x, 3.1.x, 3.2.x and 4.0.x, with ZooKeeper dependency coverage included, delivered as Docker images and Helm charts. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a multi-tenant namespace isolation audit, a JWT and TLS authentication review and ZooKeeper to Oxia migration planning, and Operate adds 24/7 broker, bookie and ZooKeeper monitoring with a 15-minute P1 response and support for Pulsar Functions and IO connectors. See Apache Pulsar support.

Tags

Apache PulsarCVEPulsar 3.0Pulsar 4.0End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.