# \[RELEASE\] ScyllaDB Java Driver 3.11.5.20

**URL:** <https://forum.scylladb.com/t/release-scylladb-java-driver-3-11-5-20/5532>\
**Category:** Release Notes\
**Tags:** release, open-source, drivers, driver-release, java-driver\
**Created:** [October 7, 2026, 4:49pm UTC](https://forum.scylladb.com/t/release-scylladb-java-driver-3-11-5-20/5532 "2026-10-07T16:49:20Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikagra](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.scylladb.com/nikagra/32/1923_2.png) [@nikagra](https://forum.scylladb.com/u/nikagra)\
**Post date:** [October 7, 2026, 4:49pm UTC](https://forum.scylladb.com/t/release-scylladb-java-driver-3-11-5-20/5532/1 "2026-10-07T16:49:20Z")

</div>

Hi everyone,

We’re happy to announce the release of **ScyllaDB Java Driver 3.11.5.20**.

This release fixes a misclassification that made server overload during authentication look like invalid credentials, and remediates a set of jackson-databind CVEs.

> **Note:** 3.x is in maintenance mode as of [3.11.5.19](https://github.com/scylladb/java-driver/releases/tag/3.11.5.19) — only critical bug fixes will be accepted on the branch. Both changes here qualify. Ongoing development is on 4.x; see [upgrading from 3.x](https://java-driver.docs.scylladb.com/stable/upgrade_guide/from_3x/).

### What’s Changed

**Bug fixes**

- **Server overload during authentication is no longer reported as bad credentials (DRIVER-1121)** ([#1160](https://github.com/scylladb/java-driver/pull/1160)). ScyllaDB returns native-protocol `OVERLOADED` rather than `BAD_CREDENTIALS` when authentication can’t proceed because the server is overloaded. Java Driver 3.x turned **every** authentication-phase error into `AuthenticationException`, so a transient load condition was indistinguishable from a wrong password — and because it looked like a credentials problem, the driver gave up on the node instead of treating it as retryable. The fix preserves `OVERLOADED` as `OverloadedException` after protocol-v1 `CREDENTIALS` and v2+ `AUTH_RESPONSE`, while `BAD_CREDENTIALS` still maps to `AuthenticationException`. Overload is also excluded from authentication-error metrics. Three recovery paths that were previously cut short now continue:

**Security**

- **jackson-databind 2.18.9 → 2.18.11** ([#1172](https://github.com/scylladb/java-driver/pull/1172)), remediating **CVE-2026-68497 (HIGH)**, CVE-2026-19032, and CVE-2026-83557. The fix landed upstream in 2.18.10; we’ve taken the latest 2.18.x patch. This also matters beyond the driver: jackson is shaded into `scylla-cdc-driver3`, so the ScyllaDB CDC Source Connector inherits whatever version is set here — these CVEs could only be cleared from this repository.

**Documentation**

- 3.x readers are now pointed at the 4.x migration guide ([#1001](https://github.com/scylladb/java-driver/pull/1001)).
- 3.11.5.19 advertised in the 3.x README ([#1168](https://github.com/scylladb/java-driver/pull/1168)).
- Maven Central badge added to the 3.x README ([#1198](https://github.com/scylladb/java-driver/pull/1198)).

### Who should upgrade

**All 3.x users.** Worth prioritising if either applies:

- You run **authentication against clusters that can get overloaded**. Before this fix, a load spike during connection setup surfaced as an authentication failure and the affected node was dropped from consideration rather than retried — which is both misleading to operators and worse for availability.
- You track **jackson CVEs** in dependency scans, or you run the **CDC Source Connector** , which picks up the fixed version through the shaded `scylla-cdc-driver3` jar.

### Download / Coordinates

xml

```xml
<dependency>
  <groupId>com.scylladb</groupId>
  <artifactId>scylla-driver-core</artifactId>
  <version>3.11.5.20</version>
</dependency>

```

### Links

- **GitHub Release:** [Release 3.11.5.20](https://github.com/scylladb/java-driver/releases/tag/3.11.5.20)
- **Full Changelog:** [Comparing 3.11.5.19…3.11.5.20](https://github.com/scylladb/java-driver/compare/3.11.5.19...3.11.5.20)
- **Java Driver 4.x:** [documentation](https://java-driver.docs.scylladb.com/stable/) · [upgrading from 3.x](https://java-driver.docs.scylladb.com/stable/upgrade_guide/from_3x/)

As always, feel free to report any issues on [GitHub](https://github.com/scylladb/java-driver/issues).
