<a id="aws-cloudwatch-logs-connector-changelog"></a>

# Changelog for Amazon CloudWatch Logs Source Connector for Confluent Platform

## Version 2.0.10

* CC-43132: Updated `io.netty` to 4.1.136.Final to fix CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-56819, CVE-2026-59898, CVE-2026-59899, CVE-2026-59900, CVE-2026-59901, and CVE-2026-59921

## Version 2.0.9

* CC-42481: Updated `com.fasterxml.jackson.core:jackson-databind` to 2.22.1 to fix CVE-2026-54515

## Version 2.0.8

* CC-42303: Updated `com.fasterxml.jackson.core:jackson-databind` to 2.22.0 to fix CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54516, CVE-2026-54517, and CVE-2026-54518
* CC-41886: Updated `io.netty:netty-handler` to 4.1.135.Final to fix CVE-2026-44249, CVE-2026-45416, and CVE-2026-50010
* CC-41887: Updated `io.netty:netty-codec-http2` to 4.1.135.Final to fix CVE-2026-47244, CVE-2026-48043, and CVE-2026-50560
* CC-42118: Updated `io.netty:netty-codec-http` to 4.1.135.Final to fix CVE-2026-50020

## Version 2.0.7

* CC-41148: Bumped `io.netty:netty-codec-http` to `4.1.133.Final`.
* CC-41221: Bumped `io.netty:netty-codec-http2` to `4.1.133.Final`.
* CC-41222: Bumped `io.netty:netty-codec` to `4.1.133.Final`.
* CC-40689: Bumped `org.apache.logging.log4j:log4j-core` to `2.25.4`.
* Merge Conflict Resolution (from 1.4.x to 2.0.x)
* Updating connect plugins parent to 0.11.8
* CC-40193: Extract region from endpoint URL when aws.cloudwatch.signing.region is not set
* CC-40193: Fix validate 500 on non-AWS environments

## Version 2.0.6

* CC-40245: Bumped `io.netty:netty-codec-http` to 4.1.132.Final to fix CVE-2026-33870
* CC-40244: Bumped `io.netty:netty-codec-http2` to 4.1.132.Final to fix CVE-2026-33871

## Version 2.0.5

* CC-39521: Updated `com.fasterxml.jackson.core:jackson-core` to address GHSA-72hv-8253-57qq
* CC-38387: Updated `org.apache.logging.log4j:log4j-core` to 2.25.3 to fix CVE-2025-68161

## Version 2.0.4

* CC-38256: Updated `io.netty:netty-codec-http` to 4.1.129.Final to fix CVE-2025-67735

## Version 2.0.3

* CC-38587: Updated `org.bitbucket.b_c:jose4j` to 0.9.6 to fix CVE-2024-29371

## Version 2.0.2

* Upgraded guava to 32.0.0-android to fix CVE vulnerability
* Surfaced `ThrottlingException` during validation
* Updated the netty version to 4.1.125.Final

## Version 2.0.1

* Updated netty codec version to `io.netty:netty-codec-http:4.1.125.Final` to resolve the critical vulnerability [CVE - 9941] discovered in `kafka-connect-aws-cloudwatch-logs:2.0.0`.

## Version 2.0.0

CC-36002: Migrated the connector to use AWS SDK v2
