[RELEASE] ScyllaDB Java Driver 3.11.5.20

Hi everyone,

We’re happy to announce the release of ScyllaDB Java Driver 3.11.5.20.

This release fixes a misclassification that made server overload during authentication look like invalid credentials, and remediates a set of jackson-databind CVEs.

Note: 3.x is in maintenance mode as of 3.11.5.19 — only critical bug fixes will be accepted on the branch. Both changes here qualify. Ongoing development is on 4.x; see upgrading from 3.x.

What’s Changed

Bug fixes

  • Server overload during authentication is no longer reported as bad credentials (DRIVER-1121) (#1160). ScyllaDB returns native-protocol OVERLOADED rather than BAD_CREDENTIALS when authentication can’t proceed because the server is overloaded. Java Driver 3.x turned every authentication-phase error into AuthenticationException, so a transient load condition was indistinguishable from a wrong password — and because it looked like a credentials problem, the driver gave up on the node instead of treating it as retryable. The fix preserves OVERLOADED as OverloadedException after protocol-v1 CREDENTIALS and v2+ AUTH_RESPONSE, while BAD_CREDENTIALS still maps to AuthenticationException. Overload is also excluded from authentication-error metrics. Three recovery paths that were previously cut short now continue:

    • initial control-connection setup advances to the next contact point,
    • dynamic pool-connection creation releases its reservation, so a later attempt can still grow the pool,
    • host-up and host-add processing keeps running when reprepare of cached statements hits authentication overload.

    Behavior change: applications may now observe OverloadedException where they previously saw AuthenticationException. There’s no public API or wire-format change, and exhausting all initial contact points still produces NoHostAvailableException with each overload retained in the per-host error map — but if you catch AuthenticationException to trigger a credentials-related code path, check that it still behaves correctly. Java Driver 4.x is unaffected: its initializer already reserves AuthenticationException for AUTH_ERROR, and other setup errors stay eligible for failover and reconnection. Reported in #1159.

Security

  • jackson-databind 2.18.9 → 2.18.11 (#1172), remediating CVE-2026-68497 (HIGH), CVE-2026-19032, and CVE-2026-83557. The fix landed upstream in 2.18.10; we’ve taken the latest 2.18.x patch. This also matters beyond the driver: jackson is shaded into scylla-cdc-driver3, so the ScyllaDB CDC Source Connector inherits whatever version is set here — these CVEs could only be cleared from this repository.

Documentation

  • 3.x readers are now pointed at the 4.x migration guide (#1001).
  • 3.11.5.19 advertised in the 3.x README (#1168).
  • Maven Central badge added to the 3.x README (#1198).

Who should upgrade

All 3.x users. Worth prioritising if either applies:

  • You run authentication against clusters that can get overloaded. Before this fix, a load spike during connection setup surfaced as an authentication failure and the affected node was dropped from consideration rather than retried — which is both misleading to operators and worse for availability.
  • You track jackson CVEs in dependency scans, or you run the CDC Source Connector, which picks up the fixed version through the shaded scylla-cdc-driver3 jar.

Download / Coordinates

xml

<dependency>
  <groupId>com.scylladb</groupId>
  <artifactId>scylla-driver-core</artifactId>
  <version>3.11.5.20</version>
</dependency>

Links

As always, feel free to report any issues on GitHub.