Ververica Platform 2.15.12
Applies toSelf-Managed v2
2 min read
On this page
Release Date: 2026-10-07
Changelog
Apache Flink®
Ververica Platform 2.15.12 supports the following versions:
- Apache Flink® 1.20
- Apache Flink® 1.19
- Apache Flink® 1.18
Ververica Platform 2.15.12 supports Apache Flink® 1.20, Apache Flink® 1.19, and Apache Flink® 1.18 under SLA.
For Stream Edition:
- 1.18.1-stream9-scala_2.12-java8
- 1.18.1-stream9-scala_2.12-java11
- 1.18.1-stream9-scala_2.12-java17
- 1.19.3-stream7-scala_2.12-java8
- 1.19.3-stream7-scala_2.12-java11
- 1.19.3-stream7-scala_2.12-java17
- 1.20.5-stream1-scala_2.12-java8
- 1.20.5-stream1-scala_2.12-java11
- 1.20.5-stream1-scala_2.12-java17
For Spring Edition the following archives are available:
This is a patch release with improvements, bug fixes, and security fixes.
Improvements
- Larger connector and UDF uploads. You can now upload custom connector and UDF JAR files of up to 500 MB, up from 150 MB. The limit is fixed and not configurable. If an ingress controller runs in front of Ververica Platform, raise its request body size limit to match. Flink session clusters still reject JAR files larger than 100 MiB, as set by the Flink
rest.server.max-content-lengthoption. - Spring Boot 4.0. Ververica Platform services now run on Spring Boot 4.0.8, which keeps the platform on a supported Spring Boot release line. The upgrade requires no action from you.
Bug Fixes
- Automatic SSL no longer overrides
security.ssl.algorithms. When you enable automatic SSL for a deployment with theflink.security.ssl.enabled: trueannotation, Ververica Platform previously replacedsecurity.ssl.algorithmswith a fixed cipher list. The configured value now follows the same precedence as every other Flink configuration option, and the default cipher list includesTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, andTLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384. - Deleting a deployment no longer leaves orphaned records. Deleting a deployment now removes all of its job, event, and savepoint records. Previously, a deployment with more than about 1,000 records of one type, or an AppManager restart during the cleanup, could leave orphaned records behind. These records were never cleaned up and could slow down AppManager startup over time. AppManager now also sweeps for orphaned records one minute after startup and then every hour, so records left behind by earlier versions are removed automatically.
Vulnerability Fixes (Inside Apache Flink®)
- The Flink images are unchanged from 2.15.11 (1.20.5-stream1, 1.19.3-stream7, 1.18.1-stream9), so there are no new fixes to report.
Vulnerability Fixes (Outside of Apache Flink®)
- Removed org.springframework.retry:spring-retry to address CVE-2026-41710
- Updated at.yawk.lz4:lz4-java to 1.12.0 to address CVE-2026-59949
- Updated com.fasterxml.jackson.core:jackson-core to 2.22.3 to address CVE-2026-89407, CVE-2026-89425
- Updated com.fasterxml.jackson.core:jackson-databind to 2.22.3 to address CVE-2026-19032, CVE-2026-68497, CVE-2026-83557, CVE-2026-91776, CVE-2026-91777
- Updated io.netty:netty-codec-http to 4.2.18.Final to address CVE-2026-59903
- Updated io.netty:netty-handler to 4.2.18.Final to address CVE-2026-75595, CVE-2026-75596
- Updated org.apache.logging.log4j:log4j-api to 2.25.5 to address CVE-2026-49844
- Updated org.apache.tomcat.embed:tomcat-embed-core to 11.0.26 to address CVE-2026-65182, CVE-2026-65905, CVE-2026-68525
- Updated org.bouncycastle:bcprov-jdk18on to 1.85 to address CVE-2026-13506, CVE-2026-8763
- Updated org.jsoup:jsoup to 1.23.2 to address CVE-2026-71497, CVE-2026-75140
- Updated org.mariadb.jdbc:mariadb-java-client to 2.7.15 to address CVE-2026-55856, CVE-2026-55857, CVE-2026-55858, CVE-2026-61700
- Updated org.mariadb.jdbc:mariadb-java-client to 3.5.9 to address CVE-2026-55856, CVE-2026-55857, CVE-2026-55858, CVE-2026-61700
- Updated org.springframework:spring-webmvc to 7.0.9 to address CVE-2026-47884
- Updated pymongo to 4.18.2 to address CVE-2026-88029, CVE-2026-96747, CVE-2026-96748, CVE-2026-96749
- Updated urllib3 to 2.8.0 to address CVE-2026-97687, CVE-2026-97688, CVE-2026-97689
Upgrade
We recommend upgrading with Helm using the following commands:
BASH
1$ helm repo add ververica https://charts.ververica.com
2$ helm repo update
3$ helm upgrade [RELEASE] ververica/ververica-platform --version 5.11.12 --values custom-values.yamlWas this helpful?