Changelog for Elasticsearch Service Sink Connector for Confluent Platform

Version 16.0.0

  • PR-940 - CC-35256: Replaced the deprecated Elasticsearch High Level REST Client org.elasticsearch.client:elasticsearch-rest-high-level-client with the Elasticsearch Java API Client co.elastic.clients:elasticsearch-java 8.19.19. The connector now supports Elasticsearch 8.x and 9.x, and no longer supports Elasticsearch 7.x or earlier. For more details, see Upgrade from version 15.x.

  • PR-940 - CC-35256: Removed the org.elasticsearch.client:elasticsearch-rest-high-level-client and org.elasticsearch:elasticsearch dependencies to fix CVE-2024-52979, CVE-2024-52980, CVE-2025-37727, and CVE-2025-37731

  • PR-940 - CC-35256: Changed max.in.flight.requests to allow the configured number of concurrent bulk requests instead of one fewer, which can change write ordering for upserts. For more details, see Upgrade from version 15.x.

  • PR-940 - CC-35256: Changed the connector to require the X-Elastic-Product: Elasticsearch response header. For more details, see Limitations.

  • PR-940 - CC-35256: Changed linger.ms=0 and bulk.size.bytes=0 to be treated as 1 ms and 1 byte respectively, with a one-time warning logged at startup. Observable behavior is unchanged.

  • PR-944 - CC-43920: Fixed an issue where, with flush.synchronously=false, consumer offsets stopped advancing when records were dropped before being written, which caused growing consumer lag and reprocessing on restart.

  • PR-948 - Fixed an issue where, with behavior.on.null.values=delete and flush.synchronously=false, a tombstone record with a null key stopped consumer offsets from advancing and could eventually stall the task.

  • PR-945 - CC-43237: Updated at.yawk.lz4:lz4-java to 1.11.3 to fix CVE-2026-59949

  • PR-945 - CC-43803: Updated org.apache.logging.log4j:log4j-api to 2.26.1 to fix CVE-2026-49844