FIND-20260404-004 · 2026-04-04 · Innovation Veille

Redpanda v26.1.2 — Critical Memory Exhaustion Fix for Audit Log RPC Accumulation

release HIGH
Redpanda v26.1.2 was released April 3, 2026. It fixes a critical production issue: slow replication could cause audit log produce RPCs to pile up unbounded, eventually exhausting memory on the server shard. Also fixes a reactor stall in the producer state cache. Improvements include enhanced principal support for security role commands and better handling of unknown cluster properties via the admin API. ODS is currently on v26.1.1.

Source

https://github.com/redpanda-data/redpanda/releases/tag/v26.1.2

ODS Impact

ODS uses Redpanda as the primary event bus for all Zero-ETL streaming between services. The memory exhaustion bug fixed in v26.1.2 is a production stability risk — under slow replication conditions (e.g., high load, network hiccups) the broker shard could run out of memory. Upgrade from v26.1.1 to v26.1.2 is strongly recommended before putting any service under production load.

Security Review

License: BSL-1.1 | Maintenance: ACTIVE | Risk: LOW | Recommendation: SAFE_TO_USE

Tags

redpanda kafka event-bus release memory stability zero-etl