Is Clarity impacted by CVE-2025-27817?
Clarity 16.2.3,16.3.3,16.4.0,16.4.1,16.4.2
A high-severity security vulnerability CVE-2025-27817 was recently disclosed affecting the Apache Kafka Client, a third-party library used for data messaging.
While the Clarity codebase does contain a version of the library that is flagged by security scanners, the vulnerability cannot be exploited in Clarity. Clarity's internal architecture acts as a strict filter, preventing the specific type of malicious input required to trigger this issue.