Hi everyone,
We’re happy to announce the release of ScyllaDB CDC Source Connector v2.0.7. This release brings per-stream parallelism for tablet-based CDC tables and two Netty security fixes, one of them CRITICAL.
What’s Changed
Security
- CVE-2026-75595 (Netty, CRITICAL, CVSS 9.1): a fragmented TLS ClientHello whose handshake header spans multiple records makes Netty fall back to the default
SslContext. Where per-SNI selection is the only mTLS gate and the fallback context is permissive, an unauthenticated client can bypass the route’s mTLS requirement (#303). - CVE-2026-75596 (Netty, MEDIUM, CVSS 6.9): the default SNI parsing path re-copies all previously received ClientHello fragments on every new record, so a peer that drips a large ClientHello in tiny records drives quadratic CPU work on the event loop before the handshake completes (#303).
Both were flagged on both paths that bring Netty into the connector — the direct scylla-driver-core dependency and the copy shaded into scylla-cdc-driver3 — and both paths are now on Netty 4.1.138.Final. No local override was needed; the fix arrives transitively.
Improvements
- Per-stream tablet CDC tasks (#300). A tablet table is now read by one task per tablet stream rather than a single task per table, so CDC on tablet-based keyspaces can be spread across Kafka Connect tasks. Raise
tasks.maxto take advantage of it. - Existing Kafka offsets are migrated automatically when you upgrade. Legacy checkpoints are used read-only to seed the new per-stream tasks, so there is no replay and no loss of initial-lookback data, and any per-stream offsets you already have stay authoritative.
- New configuration option
scylla.worker.config.max.bytes(default786432) caps the serialized size of a single worker task configuration, keeping it below Kafka’s 1 MiB record limit. Tables with very high tablet counts are packed across the available task configurations automatically; if a reconfiguration is still rejected, raisingtasks.maxis the fix. - A single Kafka Connect task can now hold assignments from multiple table generations, so configurations stay valid even at low
tasks.max.
Dependencies
scylla-driver-coreupdated from 3.11.5.18 to 3.11.5.19 (#303).scylla-cdc-javaupdated from 1.3.13 to 1.3.16 (#300, #303).
Known limitation
Legacy tablet checkpoints are not retired after migration, so each upgraded table leaves one stale key behind in connect-offsets. It is only ever read to seed a replacement task that has no offset of its own, and has no effect on correctness or on the data you receive.
Who should upgrade
Recommended for all users, and particularly if you terminate TLS with Netty’s SNI path anywhere in the same JVM, given the severity of CVE-2026-75595. If you run CDC on tablet-based keyspaces, this is also the release where increasing tasks.max starts to pay off.
Links
- Full Changelog: Comparing v2.0.6…v2.0.7
- GitHub Release: Release v2.0.7
As always, feel free to report any issues on GitHub.