<a id="kinesis-source-changelog"></a>

# Changelog for Amazon Kinesis Source Connector for Confluent Platform

## Version 2.0.12

* CC-44606: Updated `io.netty:netty-handler` to 4.1.137.Final to fix CVE-2026-75595 and CVE-2026-75596

## Version 2.0.11

* CC-43129: Updated `io.netty` to 4.1.136.Final to fix CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-56819, CVE-2026-59898, CVE-2026-59899, CVE-2026-59900, CVE-2026-59901, CVE-2026-59921, and GHSA-mfg7-5gfp-c4w3
* CC-43581: Updated `com.squareup.wire:wire-runtime-jvm` to 6.3.0 to fix CVE-2026-45799

## Version 2.0.10

* CC-42480: Updated `com.fasterxml.jackson.core:jackson-databind` to 2.22.1 to fix CVE-2026-54515

## Version 2.0.9

* CC-42302: Updated `com.fasterxml.jackson.core:jackson-databind` to 2.22.0 to fix CVE-2026-54512, CVE-2026-54513, and CVE-2026-54514
* CC-41884: Updated `io.netty:netty-handler` to 4.1.135.Final to fix CVE-2026-44249, CVE-2026-45416, and CVE-2026-50010
* CC-41885: Updated `io.netty:netty-codec-http2` to 4.1.135.Final to fix CVE-2026-47244, CVE-2026-48043, and CVE-2026-50560
* CC-41883: Updated `io.netty:netty-resolver-dns` to 4.1.135.Final to fix CVE-2026-45673, CVE-2026-45674, and CVE-2026-47691
* CC-42117: Updated `io.netty:netty-codec-http` to 4.1.135.Final to fix CVE-2026-50020
* CC-41881, CC-41882: Updated `io.netty:netty-transport-native-kqueue` and `io.netty:netty-transport-native-epoll` to 4.1.135.Final to fix CVE-2026-45536

## Version 2.0.8

* CC-41518: Updated `com.squareup.wire:wire-runtime` to `6.3.0` to fix CVE-2026-45799.

## Version 2.0.7

* CC-41147: Bumped `io.netty:netty-codec-http` to `4.1.133.Final`.
* CC-41219: Bumped `io.netty:netty-codec-http2` to `4.1.133.Final`.
* CC-41220: Bumped `io.netty:netty-codec` to `4.1.133.Final`.
* CC-41377: Bumped `org.bouncycastle:bcprov-jdk18on` to `1.84`.
* CC-41378: Bumped `org.bouncycastle:bcpkix-jdk18on` to `1.84`.
* CC-41379: Bumped `io.netty:netty-transport-native-epoll` to `4.1.133.Final`.
* CC-41380: Bumped `io.netty:netty-handler-proxy` to `4.1.133.Final`.
* CC-41381: Bumped `io.netty:netty-codec-dns` to `4.1.133.Final`.

## Version 2.0.6

* CC-39400: Pinned `com.squareup.wire:wire-runtime` to `5.2.0` to address CVE-2024-58103.

## Version 2.0.5

* CC-40243: Bumped `io.netty:netty-codec-http` to 4.1.132.Final to fix CVE-2026-33870
* CC-40242: Bumped `io.netty:netty-codec-http2` to 4.1.132.Final to fix CVE-2026-33871

## Version 2.0.4

* CC-39520: Bumped `com.fasterxml.jackson.core:jackson-core` to 2.21.1 to address GHSA-72hv-8253-57qq

## Version 2.0.3

* CC-38587: Updated `org.bitbucket.b_c:jose4j` to 0.9.6 to fix CVE-2024-29371
* CC-38255: Updated `io.netty:netty-codec-http` to 4.1.129.Final to fix CVE-2025-67735

## Version 2.0.2

* CC-37326: Pinned `com.squareup.wire:wire-runtime` to `5.2.0` to address CVE-2024-58103.

## Version 2.0.1

* CC-36468, CC-36500: Pinned `io.netty` to `4.1.125.Final` to address CVE-2025-58057 & CVE-2025-58056

## Version 2.0.0

CC-36003: Migrated the connector to use AWS SDK v2
