// OSSeva Blog
SecurityApache Pulsar Vulnerabilities by Version: CVEs for Pulsar 2.x, 3.x, 4.x and 5.0
The short answer
Pulsar 5.0.0, the first release of the next LTS line, came out on 5 October 2026, the same day as 4.0.14. The release policy gives 5.0 active support until 5 October 2028 and security support until 5 October 2029, and gives 4.0 LTS active support until 21 October 2026 and security support until 21 October 2027. Every other line is out of support: 4.2 ended on 24 September 2026, 4.1 on 8 March 2026, and 3.0 LTS lost security support on 2 May 2026. The Pulsar security page lists 20 CVEs, the most recent from April 2025, plus a set of expedited releases for the Avro flaw CVE-2024-47561. Fixes have reached some lines after their support ended, but 2.x, 3.1 and 3.2 are each missing at least two.
Pulsar release lines and their CVEs
Support dates are from the Pulsar release policy page. Each row lists the CVEs from the Pulsar security page, plus CVE-2024-47561, that name the line and have no fix on it.
| Line | Upstream status | Latest release | CVEs with no fix on this line | Upstream fix on this line |
|---|---|---|---|---|
| 5.0 LTS | Supported; active to 5 October 2028, security to 5 October 2029 | 5.0.0, 5 October 2026 | None | Not applicable |
| 4.2 | Support ended 24 September 2026 | 4.2.5 | None | Not applicable |
| 4.1 | Support ended 8 March 2026 | 4.1.3 | None | Not applicable |
| 4.0 LTS | Active to 21 October 2026, security to 21 October 2027 | 4.0.14, 5 October 2026 | None; CVE-2025-30677 affects 4.0.0 to 4.0.3 | 4.0.4 |
| 3.3 | Support ended 5 December 2024 | 3.3.9 | None; CVE-2024-47561 and CVE-2025-30677 got ad hoc fixes | 3.3.2 and 3.3.6 |
| 3.2 | Support ended 5 August 2024 | 3.2.4 | CVE-2024-47561, CVE-2025-30677 | No upstream fix on this line |
| 3.1 | Support ended 10 February 2024 | 3.1.3 | CVE-2024-29834, CVE-2024-47561, CVE-2025-30677 | No upstream fix on this line |
| 3.0 LTS | Security support ended 2 May 2026 | 3.0.17 | None so far | 3.0.3, 3.0.4, 3.0.7 and 3.0.11 carry the 2024 and 2025 fixes |
| 2.11 | Support ended 11 January 2024 | 2.11.4 | CVE-2024-29834, CVE-2024-47561, CVE-2025-30677 | No upstream fix on this line; 2.11.4 has the earlier 2024 fixes |
| 2.10 | Support ended 18 April 2023 | 2.10.6 | CVE-2023-51437, CVE-2024-29834, CVE-2024-47561, CVE-2025-30677 | No upstream fix on this line; 2.10.6 has the earlier 2024 fixes |
| 2.9 and older | 2.9 ended 20 December 2022, 2.8 on 15 June 2022 | 2.9.5; 2.8.4 | CVE-2024-27135, CVE-2024-27317, CVE-2024-27894, CVE-2022-34321, CVE-2024-28098, CVE-2023-51437, CVE-2024-29834 and the later ones; 2.8 and 2.9 also CVE-2023-37544 | No upstream fix on these lines |
The release policy says the project does not announce end of support separately, and may make ad hoc releases for older lines on a best-effort basis when a CVE is serious enough. That is how 2.10.6 and 2.11.4 came out in March 2024, eleven and two months after those lines ended, and how 3.3 got 3.3.2 and 3.3.6. None of that is guaranteed for the next CVE. For dates on every line, see the Apache Pulsar end-of-life chart.
Notable Pulsar CVEs by release line
CVSS is NVD's own score where NVD has scored the record. For CVE-2024-47561, which is in the Avro Java SDK that Pulsar bundles, NVD has no score of its own and the figure is the CVSS 3.1 score CISA-ADP added. Apache's own scores, as the CNA, often differ from NVD's: it scores the Function Worker CVEs 8.4 to 8.5 where NVD gives 9.9 for two of them. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2024-27135 | An authenticated user can run arbitrary Java code on the Function Worker, outside the function sandbox; also brokers with functionsWorkerEnabled=true | 9.9 (NVD) | 2.4.0 to 2.10.5, 2.11.0 to 2.11.3, 3.0.0 to 3.0.2, 3.1.0 to 3.1.2, 3.2.0 | 2.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1 |
| CVE-2024-27317 | A crafted jar or nar uploaded to the Function Worker writes files outside the extraction directory | 9.9 (NVD) | Same as CVE-2024-27135 | 2.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1 |
| CVE-2021-22160 | JWT authentication accepts tokens with the "none" algorithm, so anyone can connect as any user | 9.8 (NVD) | Before 2.7.1 | 2.7.1 |
| CVE-2024-27894 | Functions created from a URL let an authenticated user read local files and use the worker as an HTTP proxy | 8.8 (NVD) | Same as CVE-2024-27135 | 2.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1 |
| CVE-2023-30429 | Behind a proxy using mTLS, the Function Worker authorizes requests with the proxy's role instead of the client's | 8.8 (NVD) | Before 2.10.4; 2.11.0 | 2.10.4, 2.11.1 |
| CVE-2022-34321 | The proxy's /proxy-stats endpoint needs no authentication and can change proxied connections' logging level | 8.2 (NVD) | 2.6.0 to 2.10.5, 2.11.0 to 2.11.2, 3.0.0 to 3.0.1, 3.1.0 | 2.10.6, 2.11.3, 3.0.2, 3.1.1 |
| CVE-2023-30428 | A custom header on the broker's REST producer lets an authenticated user produce to any topic with the broker's admin role | 8.1 (NVD) | 2.9.0 to 2.9.5, 2.10.0 to 2.10.3, 2.11.0 | 2.10.4, 2.11.1 |
| CVE-2023-37544 | The WebSocket proxy's /pingpong endpoint accepts unauthenticated connections | 7.5 (NVD) | 2.8.x, 2.9.x, 2.10.0 to 2.10.4, 2.11.0 to 2.11.1, 3.0.0 | 2.10.5, 2.11.2, 3.0.1 |
| CVE-2023-51437 | A timing side channel lets an attacker forge a SASL role token that passes signature checks | 7.4 (NVD) | Through 2.10.5, 2.11.0 to 2.11.2, 3.0.0 to 3.0.1, 3.1.0 | 2.11.3, 3.0.2, 3.1.1 |
| CVE-2024-47561 | Schema parsing in the bundled Avro Java SDK before 1.11.4 allows code execution | 7.3 (CISA-ADP) | Pulsar releases with Avro 1.11.3 or older, in servers and the Java client | 3.0.7, 3.3.2, 4.0.0 |
| CVE-2025-30677 | The Kafka source, sink and Kafka Connect adaptor connectors log Kafka credentials in plain text | 6.5 (NVD) | All versions before 3.0.11, 3.3.6 and 4.0.4 | 3.0.11, 3.3.6, 4.0.4 |
| CVE-2024-29834 | Users with only produce or consume permission can unload partitioned topics, trigger compaction and change subscription properties | 6.4 (NVD) | 2.7.1 to 2.10.6, 2.11.0 to 2.11.4, 3.0.0 to 3.0.3, 3.1.0 to 3.1.3, 3.2.0 to 3.2.1 | 3.0.4, 3.2.2 |
| CVE-2024-28098 | Users with only produce or consume permission can change topic-level retention, TTL and offload policies | 5.4 (NVD) | 2.7.1 to 2.10.5, 2.11.0 to 2.11.3, 3.0.0 to 3.0.2, 3.1.0 to 3.1.2, 3.2.0 | 2.10.6, 2.11.4, 3.0.3, 3.1.3, 3.2.1 |
Most of this list comes down to two features. The first is Pulsar Functions: CVE-2024-27135, CVE-2024-27317, CVE-2024-27894, CVE-2023-30429 and CVE-2023-37579 all need the Function Worker, either as a separate service or inside the broker with functionsWorkerEnabled=true, and a cluster that does not run Functions is not exposed to them. The second is multi-tenant authorization: CVE-2024-28098, CVE-2024-29834 and CVE-2023-30428 let a tenant with ordinary produce or consume rights act beyond them, which matters most where several teams share one cluster. CVE-2024-47561 is different, because Avro is in the Java client as well as the brokers, so applications need the newer client too.
What each line gets
Pulsar 5.0 LTS
5.0.0 is the newest release and the start of the next LTS line. The policy supports live upgrade and downgrade from one LTS to the next, so 4.0 to 5.0 is the planned path, while 3.x to 5.0 is not supported in one step.
Pulsar 4.0 LTS
4.0.14 carries every fix above that applies to 4.0, and 4.0.0 already shipped Avro 1.11.4. Active support ends on 21 October 2026, after which 4.0 gets security fixes only until 21 October 2027. See Apache Pulsar 4.0 end of life.
Pulsar 4.1 and 4.2
Feature releases get six months of support. No advisory names 4.1 or 4.2, but neither line will get the fix for the next CVE, so the move from either is to 5.0 or back onto the 4.0 LTS line.
Pulsar 3.3, 3.2 and 3.1
These feature lines ended in 2024. 3.3 received ad hoc releases with the fixes for CVE-2024-47561 and CVE-2025-30677, so 3.3.9 has every fix above. 3.2.4 and 3.1.3 do not: both still bundle the vulnerable Avro, and 3.1 also has no fix for CVE-2024-29834, whose advisory sends 3.1 users to 3.2.2. The policy allows live upgrade from 3.2 to 4.0.
Pulsar 3.0 LTS
3.0 lost security support on 2 May 2026. Its last release, 3.0.17, carries every fix above, so the reason to move is that the next CVE will not reach it. The live upgrade path is 3.0 to 4.0; see the Pulsar 3.0 to 4.0 upgrade guide and Apache Pulsar 3.0 end of life.
Pulsar 2.10, 2.11 and older
2.10.6 and 2.11.4 carry the March 2024 Function Worker and proxy fixes, but not the April 2024 fix for CVE-2024-29834, nor the Avro or Kafka connector fixes. The CVE-2023-51437 advisory, for the SASL token forgery, names no 2.10 fix and sends 2.10 users to 2.11.3 or later. 2.9 and older have none of the 2024 fixes, including the Function Worker remote code execution, and 2.8 and 2.9 also lack the WebSocket proxy fix. Before 3.0 the policy requires upgrading one feature version at a time, so getting from 2.10 to 3.0 means passing through 2.11. 2.x clusters also run on ZooKeeper; see ZooKeeper for Pulsar.
What to do on each line
- 5.0 and 4.0. Take each patch release, and plan the move from 4.0 to 5.0 before 4.0 security support ends in October 2027.
- 4.1 and 4.2. Move to 5.0.
- 3.x. Move to 4.0 with a live upgrade, then to 5.0. The policy's own examples include 3.0 to 4.0 and 3.2 to 4.0.
- 2.x. Upgrade feature by feature to 3.0, or take patched builds from a supplier that backports fixes. Until then, disable the Function Worker if you do not use Functions, keep the proxy and its admin endpoints off untrusted networks, and review which roles hold produce and consume rights across tenants.
- Every line. Upgrade the Pulsar Java client in applications to 3.0.7, 3.3.2, 4.0.0 or later for CVE-2024-47561, whatever version the brokers run.
Where OSSeva fits
OSSeva ships CVE-patched, GPG-signed Pulsar builds for 2.10.x, 2.11.x, 3.0.x, 3.1.x, 3.2.x and 4.0.x, with ZooKeeper dependency coverage included, delivered as Docker images and Helm charts. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a multi-tenant namespace isolation audit, a JWT and TLS authentication review and ZooKeeper to Oxia migration planning, and Operate adds 24/7 broker, bookie and ZooKeeper monitoring with a 15-minute P1 response and support for Pulsar Functions and IO connectors. See Apache Pulsar support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.