Hi everyone,
We’re happy to announce the release of ScyllaDB Java Driver 3.11.5.20.
This release fixes a misclassification that made server overload during authentication look like invalid credentials, and remediates a set of jackson-databind CVEs.
Note: 3.x is in maintenance mode as of 3.11.5.19 — only critical bug fixes will be accepted on the branch. Both changes here qualify. Ongoing development is on 4.x; see upgrading from 3.x.
What’s Changed
Bug fixes
-
Server overload during authentication is no longer reported as bad credentials (DRIVER-1121) (#1160). ScyllaDB returns native-protocol
OVERLOADEDrather thanBAD_CREDENTIALSwhen authentication can’t proceed because the server is overloaded. Java Driver 3.x turned every authentication-phase error intoAuthenticationException, so a transient load condition was indistinguishable from a wrong password — and because it looked like a credentials problem, the driver gave up on the node instead of treating it as retryable. The fix preservesOVERLOADEDasOverloadedExceptionafter protocol-v1CREDENTIALSand v2+AUTH_RESPONSE, whileBAD_CREDENTIALSstill maps toAuthenticationException. Overload is also excluded from authentication-error metrics. Three recovery paths that were previously cut short now continue:- initial control-connection setup advances to the next contact point,
- dynamic pool-connection creation releases its reservation, so a later attempt can still grow the pool,
- host-up and host-add processing keeps running when reprepare of cached statements hits authentication overload.
Behavior change: applications may now observe
OverloadedExceptionwhere they previously sawAuthenticationException. There’s no public API or wire-format change, and exhausting all initial contact points still producesNoHostAvailableExceptionwith each overload retained in the per-host error map — but if you catchAuthenticationExceptionto trigger a credentials-related code path, check that it still behaves correctly. Java Driver 4.x is unaffected: its initializer already reservesAuthenticationExceptionforAUTH_ERROR, and other setup errors stay eligible for failover and reconnection. Reported in #1159.
Security
- jackson-databind 2.18.9 → 2.18.11 (#1172), remediating CVE-2026-68497 (HIGH), CVE-2026-19032, and CVE-2026-83557. The fix landed upstream in 2.18.10; we’ve taken the latest 2.18.x patch. This also matters beyond the driver: jackson is shaded into
scylla-cdc-driver3, so the ScyllaDB CDC Source Connector inherits whatever version is set here — these CVEs could only be cleared from this repository.
Documentation
- 3.x readers are now pointed at the 4.x migration guide (#1001).
- 3.11.5.19 advertised in the 3.x README (#1168).
- Maven Central badge added to the 3.x README (#1198).
Who should upgrade
All 3.x users. Worth prioritising if either applies:
- You run authentication against clusters that can get overloaded. Before this fix, a load spike during connection setup surfaced as an authentication failure and the affected node was dropped from consideration rather than retried — which is both misleading to operators and worse for availability.
- You track jackson CVEs in dependency scans, or you run the CDC Source Connector, which picks up the fixed version through the shaded
scylla-cdc-driver3jar.
Download / Coordinates
xml
<dependency>
<groupId>com.scylladb</groupId>
<artifactId>scylla-driver-core</artifactId>
<version>3.11.5.20</version>
</dependency>
Links
- GitHub Release: Release 3.11.5.20
- Full Changelog: Comparing 3.11.5.19…3.11.5.20
- Java Driver 4.x: documentation · upgrading from 3.x
As always, feel free to report any issues on GitHub.