---
title: "Aerospike Connect for Event Stream Processing (ESP) release notes"
description: "Aerospike Connect for Event Stream Processing (ESP) release notes covering versions 1.0.0 through 3.0.6."
---

# Aerospike Connect for Event Stream Processing (ESP) release notes

> For the complete documentation index see: [llms.txt](https://aerospike.com/docs/llms.txt)
> 
> All documentation pages available in markdown.

## Connect for Event Stream Processing (ESP) 3.0.6

September 1, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

### Security

-   \[Streaming\] Aerospike Streaming Connectors - Security vulnerabilities: [CVE-2024-7254](https://www.cve.org/CVERecord?id=CVE-2024-7254), [CVE-2026-8384](https://www.cve.org/CVERecord?id=CVE-2026-8384), [CVE-2026-33870](https://www.cve.org/CVERecord?id=CVE-2026-33870), [CVE-2026-33871](https://www.cve.org/CVERecord?id=CVE-2026-33871), [CVE-2026-42579](https://www.cve.org/CVERecord?id=CVE-2026-42579), [CVE-2026-42581](https://www.cve.org/CVERecord?id=CVE-2026-42581), [CVE-2026-42583](https://www.cve.org/CVERecord?id=CVE-2026-42583), [CVE-2026-42584](https://www.cve.org/CVERecord?id=CVE-2026-42584), [CVE-2026-42585](https://www.cve.org/CVERecord?id=CVE-2026-42585), [CVE-2026-42586](https://www.cve.org/CVERecord?id=CVE-2026-42586), [CVE-2026-42587](https://www.cve.org/CVERecord?id=CVE-2026-42587), [CVE-2026-44249](https://www.cve.org/CVERecord?id=CVE-2026-44249), [CVE-2026-44250](https://www.cve.org/CVERecord?id=CVE-2026-44250), [CVE-2026-44890](https://www.cve.org/CVERecord?id=CVE-2026-44890), [CVE-2026-44891](https://www.cve.org/CVERecord?id=CVE-2026-44891), [CVE-2026-44893](https://www.cve.org/CVERecord?id=CVE-2026-44893), [CVE-2026-45416](https://www.cve.org/CVERecord?id=CVE-2026-45416), [CVE-2026-45674](https://www.cve.org/CVERecord?id=CVE-2026-45674), [CVE-2026-46340](https://www.cve.org/CVERecord?id=CVE-2026-46340), [CVE-2026-47691](https://www.cve.org/CVERecord?id=CVE-2026-47691), [CVE-2026-48006](https://www.cve.org/CVERecord?id=CVE-2026-48006), [CVE-2026-48059](https://www.cve.org/CVERecord?id=CVE-2026-48059), [CVE-2026-50010](https://www.cve.org/CVERecord?id=CVE-2026-50010), [CVE-2026-50011](https://www.cve.org/CVERecord?id=CVE-2026-50011), [CVE-2026-55831](https://www.cve.org/CVERecord?id=CVE-2026-55831), [CVE-2026-55833](https://www.cve.org/CVERecord?id=CVE-2026-55833), [CVE-2026-55851](https://www.cve.org/CVERecord?id=CVE-2026-55851), [CVE-2026-56745](https://www.cve.org/CVERecord?id=CVE-2026-56745), [CVE-2026-56817](https://www.cve.org/CVERecord?id=CVE-2026-56817), [CVE-2026-56819](https://www.cve.org/CVERecord?id=CVE-2026-56819), [CVE-2026-56820](https://www.cve.org/CVERecord?id=CVE-2026-56820), [CVE-2026-56821](https://www.cve.org/CVERecord?id=CVE-2026-56821), [CVE-2026-56822](https://www.cve.org/CVERecord?id=CVE-2026-56822), [CVE-2026-59901](https://www.cve.org/CVERecord?id=CVE-2026-59901), [CVE-2026-59902](https://www.cve.org/CVERecord?id=CVE-2026-59902), [CVE-2026-59903](https://www.cve.org/CVERecord?id=CVE-2026-59903), [CVE-2026-59920](https://www.cve.org/CVERecord?id=CVE-2026-59920), [CVE-2026-73507](https://www.cve.org/CVERecord?id=CVE-2026-73507), and [CVE-2026-75595](https://www.cve.org/CVERecord?id=CVE-2026-75595). \[CONNECTOR-1652\]

---

## Connect for Event Stream Processing (ESP) 3.0.5

August 9 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 17 or later.**

### Security

-   \[Streaming\] Aerospike Streaming Connectors - Security vulnerabilities: [CVE-2026-8384](https://www.cve.org/CVERecord?id=CVE-2026-8384), [CVE-2026-8763](https://www.cve.org/CVERecord?id=CVE-2026-8763), [CVE-2026-12185](https://www.cve.org/CVERecord?id=CVE-2026-12185), [CVE-2026-12802](https://www.cve.org/CVERecord?id=CVE-2026-12802), [CVE-2026-12803](https://www.cve.org/CVERecord?id=CVE-2026-12803), [CVE-2026-12816](https://www.cve.org/CVERecord?id=CVE-2026-12816), [CVE-2026-12860](https://www.cve.org/CVERecord?id=CVE-2026-12860), [CVE-2026-13506](https://www.cve.org/CVERecord?id=CVE-2026-13506), [CVE-2026-13586](https://www.cve.org/CVERecord?id=CVE-2026-13586), [CVE-2026-14682](https://www.cve.org/CVERecord?id=CVE-2026-14682), [CVE-2026-15055](https://www.cve.org/CVERecord?id=CVE-2026-15055), [CVE-2026-49844](https://www.cve.org/CVERecord?id=CVE-2026-49844), [CVE-2026-58059](https://www.cve.org/CVERecord?id=CVE-2026-58059), [CVE-2026-58060](https://www.cve.org/CVERecord?id=CVE-2026-58060), [CVE-2026-58061](https://www.cve.org/CVERecord?id=CVE-2026-58061), [CVE-2026-58062](https://www.cve.org/CVERecord?id=CVE-2026-58062), [CVE-2026-58063](https://www.cve.org/CVERecord?id=CVE-2026-58063), [CVE-2026-59639](https://www.cve.org/CVERecord?id=CVE-2026-59639), [CVE-2026-59642](https://www.cve.org/CVERecord?id=CVE-2026-59642), [CVE-2026-59645](https://www.cve.org/CVERecord?id=CVE-2026-59645), [CVE-2026-59647](https://www.cve.org/CVERecord?id=CVE-2026-59647), [CVE-2026-59650](https://www.cve.org/CVERecord?id=CVE-2026-59650), [CVE-2026-59651](https://www.cve.org/CVERecord?id=CVE-2026-59651), and [CVE-2026-59949](https://www.cve.org/CVERecord?id=CVE-2026-59949). \[CONNECTOR-1617\]

---

## Connect for Event Stream Processing (ESP) 3.0.4

July 23, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 17 or later.**

### Improvements

-   Add Custom Extension Processing Timers to Connector Metrics. \[CONNECTOR-1455\]

### Security

-   \[Streaming\] Aerospike Streaming Connectors - Security vulnerabilities: [CVE-2026-5450](https://www.cve.org/CVERecord?id=CVE-2026-5450), [CVE-2026-9563](https://www.cve.org/CVERecord?id=CVE-2026-9563), [CVE-2026-13006](https://www.cve.org/CVERecord?id=CVE-2026-13006), [CVE-2026-15308](https://www.cve.org/CVERecord?id=CVE-2026-15308), [CVE-2026-48864](https://www.cve.org/CVERecord?id=CVE-2026-48864), [CVE-2026-54399](https://www.cve.org/CVERecord?id=CVE-2026-54399), [CVE-2026-54428](https://www.cve.org/CVERecord?id=CVE-2026-54428), [CVE-2026-55833](https://www.cve.org/CVERecord?id=CVE-2026-55833), [CVE-2026-56745](https://www.cve.org/CVERecord?id=CVE-2026-56745), and [CVE-2026-59889](https://www.cve.org/CVERecord?id=CVE-2026-59889). \[CONNECTOR-1558\]

---

## Connect for Event Stream Processing (ESP) 3.0.3

June 26, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 17 or later.**

### Improvements

-   Add extra logging to ease debugging. \[CONNECTOR-1492\]
-   Read `gradle.properties` secrets through environment variables. \[CONNECTOR-1512\]

### Security

-   \[Streaming\] Aerospike Streaming Connectors - Security vulnerabilities: [CVE-2026-3260](https://www.cve.org/CVERecord?id=CVE-2026-3260), [CVE-2026-4519](https://www.cve.org/CVERecord?id=CVE-2026-4519), [CVE-2026-4786](https://www.cve.org/CVERecord?id=CVE-2026-4786), [CVE-2026-6100](https://www.cve.org/CVERecord?id=CVE-2026-6100), [CVE-2026-40355](https://www.cve.org/CVERecord?id=CVE-2026-40355), [CVE-2026-40356](https://www.cve.org/CVERecord?id=CVE-2026-40356), [CVE-2026-42577](https://www.cve.org/CVERecord?id=CVE-2026-42577), [CVE-2026-42581](https://www.cve.org/CVERecord?id=CVE-2026-42581), [CVE-2026-42583](https://www.cve.org/CVERecord?id=CVE-2026-42583), [CVE-2026-42584](https://www.cve.org/CVERecord?id=CVE-2026-42584), [CVE-2026-42585](https://www.cve.org/CVERecord?id=CVE-2026-42585), [CVE-2026-42587](https://www.cve.org/CVERecord?id=CVE-2026-42587), [CVE-2026-44249](https://www.cve.org/CVERecord?id=CVE-2026-44249), [CVE-2026-45292](https://www.cve.org/CVERecord?id=CVE-2026-45292), [CVE-2026-45416](https://www.cve.org/CVERecord?id=CVE-2026-45416), [CVE-2026-50010](https://www.cve.org/CVERecord?id=CVE-2026-50010), [CVE-2026-54512](https://www.cve.org/CVERecord?id=CVE-2026-54512), [CVE-2026-54513](https://www.cve.org/CVERecord?id=CVE-2026-54513), [CVE-2026-54514](https://www.cve.org/CVERecord?id=CVE-2026-54514), [CVE-2026-54516](https://www.cve.org/CVERecord?id=CVE-2026-54516), [CVE-2026-54517](https://www.cve.org/CVERecord?id=CVE-2026-54517), and [CVE-2026-54518](https://www.cve.org/CVERecord?id=CVE-2026-54518). \[CONNECTOR-1471\]

---

## Connect for Event Stream Processing (ESP) 3.0.1

May 6, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 17 or later.**

### Security

-   Aerospike Connectors - Security vulnerabilities and dependency upgrades - May 2026: [CVE-2026-22007](https://github.com/advisories/GHSA-rj5j-26xx-hh3v), [CVE-2026-22013](https://github.com/advisories/GHSA-75hh-423h-rvwg), [CVE-2026-22016](https://github.com/advisories/GHSA-9m62-hmpm-rr2m), [CVE-2026-22018](https://github.com/advisories/GHSA-376j-8f52-gp2x), [CVE-2026-22021](https://github.com/advisories/GHSA-9grw-5h83-65p3), [CVE-2026-23865](https://github.com/advisories/GHSA-878v-mxg6-vj8f), [CVE-2026-34268](https://github.com/advisories/GHSA-xvmr-9p7m-jmwv), [CVE-2026-34282](https://github.com/advisories/GHSA-hpm9-74qx-6x32), CWE-770 \[CONNECTOR-1431\]

---

## Connect for Event Stream Processing (ESP) 3.0.0

April 27, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 17 or later.**
    -   Starting from this release, the aerospike-esp-outbound connector requires Java runtime 17 or later. This is due to an update of dependent modules that address security vulnerabilities which now require a Java 17 or later runtime.

### Security

-   Upgrade Jetty to v12.x to fix security vulnerabilities: [CVE-2026-2332](https://github.com/advisories/GHSA-355h-qmc2-wpwf), [CVE-2024-6763](https://github.com/advisories/GHSA-qh8g-58pp-2wxh). \[CONNECTOR-1432\]

---

## Connect for Event Stream Processing (ESP) 2.4.17

April 20, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Aerospike Connectors - Security vulnerabilities and dependency upgrades - April 2026: [CVE-2024-6763](https://github.com/advisories/GHSA-qh8g-58pp-2wxh), CVE-2025-8671, [CVE-2025-8916](https://github.com/advisories/GHSA-4cx2-fc23-5wg6), [CVE-2026-3260](https://github.com/advisories/GHSA-3x3v-w654-m28m), [CVE-2026-4111](https://github.com/advisories/GHSA-xrqh-48jh-pjv2), [CVE-2026-4519](https://github.com/advisories/GHSA-rm92-fj5q-mpj5), [CVE-2026-33870](https://github.com/advisories/GHSA-pwqr-wmgm-9rr8) \[CONNECTOR-1379\]

---

## Connect for Event Stream Processing (ESP) 2.4.16

March 12, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Aerospike Connectors - Security vulnerabilities and dependency upgrades - March 2026 - CWE-770, [CVE-2025-33042](https://github.com/advisories/GHSA-rp46-r563-jrc7), [CVE-2026-24308](https://github.com/advisories/GHSA-crhr-qqj8-rpxc). \[CONNECTOR-1359, CONNECTOR-1368\]

---

## Connect for Event Stream Processing (ESP) 2.4.15

February 1, 2026  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Aerospike Connectors - Security vulnerabilities and dependency upgrades - February 2026 - [CVE-2025-11187](https://github.com/advisories/GHSA-hpc7-gcqm-58fv), [CVE-2025-15467](https://github.com/advisories/GHSA-wvhq-3h88-rf6g), [CVE-2025-15468](https://github.com/advisories/GHSA-rhx3-fg8p-f9m4), [CVE-2025-15469](https://github.com/advisories/GHSA-v2vr-926q-29fr), CVE-2025-64720, CVE-2025-65018, [CVE-2025-66199](https://github.com/advisories/GHSA-5888-36j9-c92p), [CVE-2025-68160](https://github.com/advisories/GHSA-g78j-46j5-97cr), [CVE-2025-68973](https://github.com/advisories/GHSA-pj23-86ww-f72p), [CVE-2025-69418](https://github.com/advisories/GHSA-78qr-24v5-7q73), [CVE-2025-69419](https://github.com/advisories/GHSA-x77r-97gw-wh89), [CVE-2025-69420](https://github.com/advisories/GHSA-w42r-ph9f-9x66), [CVE-2025-69421](https://github.com/advisories/GHSA-w9rv-xc8m-cmqp), [CVE-2026-21452](https://github.com/advisories/GHSA-cw39-r4h6-8j3x), [CVE-2026-21925](https://github.com/advisories/GHSA-jhg6-g5fp-536p), [CVE-2026-21933](https://github.com/advisories/GHSA-5rm3-299f-6m9v), [CVE-2026-21945](https://github.com/advisories/GHSA-r2mr-x4h2-9chr), [CVE-2026-22795](https://github.com/advisories/GHSA-3vqq-45qg-2xf6), [CVE-2026-22796](https://github.com/advisories/GHSA-r9hf-rxjm-gv2f). \[CONNECTOR-1321\]

### Improvements

-   Enhance record-ordering handling for hot key scenario. \[CONNECTOR-1320\]
-   Normalize streaming connector’s Helm chart default `values.yaml` with simplified minimal configuration. \[CONNECTOR-1322\]

---

## Connect for Event Stream Processing (ESP) 2.4.14

December 15, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Aerospike Connectors - Security vulnerabilities and dependency upgrades - December 2025 - [CVE-2024-6763](https://github.com/advisories/GHSA-qh8g-58pp-2wxh), [CVE-2025-4598](https://github.com/advisories/GHSA-jx2m-wgq5-5qcj), [CVE-2025-6965](https://github.com/advisories/GHSA-2m69-gcr7-jv3q), [CVE-2025-8916](https://github.com/advisories/GHSA-4cx2-fc23-5wg6), CVE-2025-9230, [CVE-2025-9714](https://github.com/advisories/GHSA-fmj5-rvmp-845r), [CVE-2025-12183](https://github.com/advisories/GHSA-vqf4-7m7x-wgfc), [CVE-2025-58457](https://github.com/advisories/GHSA-2hmj-97jw-28jh), [CVE-2025-59375](https://github.com/advisories/GHSA-vjqp-pjp6-xcxx). \[CONNECTOR-1303\]

### Improvements

-   Implement Github Action for connector artifact signing and upload to repository. \[CONNECTOR-1309\]

---

## Connect for Event Stream Processing (ESP) 2.4.13

November 11, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Improvements

-   Upgraded the connector’s logging and other dependencies. \[CONNECTOR-1242\]

---

## Connect for Event Stream Processing (ESP) 2.4.12

September 29, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Improvements

-   Added support for Debian 13 “Trixie” \[CONNECTOR-1215\]

### Security

-   Fixed - Aerospike Connectors - Security vulnerabilities - [CVE-2025-58056](https://github.com/advisories/GHSA-fghv-69vj-qj49), [CVE-2025-58057](https://github.com/advisories/GHSA-3p8m-j85q-pgmj), CVE-2025-58060, CVE-2025-58364 \[CONNECTOR-1272\]

---

## Connect for Event Stream Processing (ESP) 2.4.11

August 25, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed - Aerospike Connectors - Security vulnerabilities - [CVE-2025-8916](https://github.com/advisories/GHSA-4cx2-fc23-5wg6), [CVE-2025-8058](https://github.com/advisories/GHSA-8xjp-c72j-67q8), [CVE-2025-7425](https://github.com/advisories/GHSA-8c4w-j52q-j4jq), [CVE-2025-6965](https://github.com/advisories/GHSA-2m69-gcr7-jv3q), [CVE-2025-5914](https://github.com/advisories/GHSA-7376-x4rm-3v8x), [CVE-2025-32415](https://github.com/advisories/GHSA-w8fw-fj9q-vcjj), [CVE-2025-32414](https://github.com/advisories/GHSA-mfrm-w63c-3x58), [CVE-2022-29458](https://github.com/advisories/GHSA-jh4f-5j2m-4v9c). \[CONNECTOR-1262\]

---

## Connect for Event Stream Processing (ESP) 2.4.10

July 28, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed - Aerospike Connectors - Security vulnerabilities - [CVE-2024-12718](https://github.com/advisories/GHSA-2pg8-h2j6-28xm), [CVE-2025-4138](https://github.com/advisories/GHSA-4g4g-fqw4-prp2), [CVE-2025-4330](https://github.com/advisories/GHSA-68pj-xrp5-vccj), [CVE-2025-4435](https://github.com/advisories/GHSA-p72v-37h5-753v), [CVE-2025-4517](https://github.com/advisories/GHSA-6r6c-684h-9j7p), CVE-2025-6020, [CVE-2025-6021](https://github.com/advisories/GHSA-32vr-5hxf-x93f), [CVE-2025-30749](https://github.com/advisories/GHSA-3v8g-f9px-h942), [CVE-2025-47273](https://github.com/advisories/GHSA-5rjg-fvgr-3xxf), [CVE-2025-48924](https://github.com/advisories/GHSA-j288-q9x7-2f5v), [CVE-2025-49794](https://github.com/advisories/GHSA-qg4c-8pj4-qgw2), [CVE-2025-49796](https://github.com/advisories/GHSA-83xx-9f6p-vwfj), [CVE-2025-50106](https://github.com/advisories/GHSA-328q-mjp3-hwmg). \[CONNECTOR-1253\]

---

## Connect for Event Stream Processing (ESP) 2.4.9

July 16, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed - Aerospike Connectors - Security vulnerabilities - [CVE-2024-12718](https://github.com/advisories/GHSA-2pg8-h2j6-28xm), [CVE-2025-4138](https://github.com/advisories/GHSA-4g4g-fqw4-prp2), [CVE-2025-4330](https://github.com/advisories/GHSA-68pj-xrp5-vccj), [CVE-2025-4435](https://github.com/advisories/GHSA-p72v-37h5-753v), [CVE-2025-4517](https://github.com/advisories/GHSA-6r6c-684h-9j7p), CVE-2025-6020, [CVE-2025-6021](https://github.com/advisories/GHSA-32vr-5hxf-x93f), [CVE-2025-48924](https://github.com/advisories/GHSA-j288-q9x7-2f5v), [CVE-2025-49794](https://github.com/advisories/GHSA-qg4c-8pj4-qgw2), [CVE-2025-49796](https://github.com/advisories/GHSA-83xx-9f6p-vwfj). \[CONNECTOR-1253\]

---

## Connect for Event Stream Processing (ESP) 2.4.8

June 19, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed - Aerospike Connectors - Security vulnerabilities - [CVE-2025-0395](https://github.com/advisories/GHSA-4xpw-6594-8f5m), [CVE-2025-3576](https://github.com/advisories/GHSA-rfh5-gx7w-h7v7), [CVE-2025-4802](https://github.com/advisories/GHSA-8mm9-c4mg-vfjh), [CVE-2024-8176](https://github.com/advisories/GHSA-9hcv-xw76-m4h6), [CVE-2024-12133](https://github.com/advisories/GHSA-j3qr-8f3v-fgjj), [CVE-2024-12243](https://github.com/advisories/GHSA-cqj4-fp95-jqxq), [CVE-2025-32414](https://github.com/advisories/GHSA-mfrm-w63c-3x58), [CVE-2025-48734](https://github.com/advisories/GHSA-wxr5-93ph-8wr9). \[CONNECTOR-1236\]

---

## Connect for Event Stream Processing (ESP) 2.4.7

April 11, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Bug Fixes

-   Changed default value of socket-receive-buffer-bytes to null from 32kb, so this is optional configuration validation only if configured. \[CONNECTOR-1219\]

### Security

-   Aerospike Connectors - Security vulnerabilities introduced through libxml2. \[CONNECTOR-1220\]

---

## Connect for Event Stream Processing (ESP) 2.4.6

March 03, 2025  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### New Features

-   Use sendTimeout as configured without doubling. \[CONNECTOR-1183\]
-   Converted transaction debug level messages to trace level. \[CONNECTOR-1184\]
-   Kotlin version upgraded to 2.x. \[CONNECTOR-1185\]

### Security

-   Updated logback-core to 1.5.15 version to fix [CVE-2024-12798](https://github.com/advisories/GHSA-pr98-23f8-jwxv), [CVE-2024-12801](https://github.com/advisories/GHSA-6v67-2wr5-gvf4). \[CONNECTOR-1175\]
-   Updated logback-core to 1.5.15 version to fix [CVE-2024-12801](https://github.com/advisories/GHSA-6v67-2wr5-gvf4). \[CONNECTOR-1179\]
-   Updated logback-classic to 1.5.15 version to fix [CVE-2024-12798](https://github.com/advisories/GHSA-pr98-23f8-jwxv). \[CONNECTOR-1180\]
-   Updated logback-core to 1.5.15 version to fix [CVE-2024-12798](https://github.com/advisories/GHSA-pr98-23f8-jwxv). \[CONNECTOR-1181\]
-   Updated io.netty:netty-handler to 4.1.118.Final to fix [CVE-2025-24970](https://github.com/advisories/GHSA-4g8c-wm8x-jfhw), [CVE-2025-25193](https://github.com/advisories/GHSA-389x-839f-4rhx), [CVE-2024-29025](https://github.com/advisories/GHSA-5jpm-x58v-624v), [CVE-2024-47554](https://github.com/advisories/GHSA-78wr-2p64-hpwj), [CVE-2023-46120](https://github.com/advisories/GHSA-mm8h-8587-p46h) (rabbitmq), [CVE-2024-51504](https://github.com/advisories/GHSA-g93m-8x6h-g5gv) (zookeeper). \[CONNECTOR-1188\]

---

## Connect for Event Stream Processing (ESP) 2.4.5

November 07, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed security vulnerability - Authentication Bypass in krb5-libs. \[CONNECTOR-1160\]

---

## Connect for Event Stream Processing (ESP) 2.4.4

October 24, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fixed Deserialization of Untrusted Data in org.apache.avro:avro:1.11.3. \[CONNECTOR-1149\]
-   Fixed Denial of Service (DoS) in com.fasterxml.jackson.core:jackson-core. \[CONNECTOR-1149\]
-   Fixed Race Condition in io.undertow:undertow-core. \[CONNECTOR-1149\]
-   Fixed Uncontrolled Resource Consumption in commons-io:commons-io. \[CONNECTOR-1149\]

---

## Connect for Event Stream Processing (ESP) 2.4.3

September 19, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### New Features

-   Netty buffer customization changes in connectors and Kafka Outbound Await Metrics for better monitoring. \[CONNECTOR-1127\]
-   Logging improvement - Outbound Await Metrics for all applicable connectors. \[CONNECTOR-1137\]

### Security

-   Fix Arbitrary Code Injection affecting platform-python-setuptools & python3-setuptools-wheel. \[CONNECTOR-1135\]
-   Upgraded Pulsar version.

---

## Connect for Event Stream Processing (ESP) 2.4.2

July 25, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fix Race Condition. \[CONNECTOR-1105\]
-   Fix Uncontrolled Resource Consumption (‘Resource Exhaustion’). \[CONNECTOR-1108\]

---

## Connect for Event Stream Processing (ESP) 2.4.1

June 07, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Fix Improper Input Validation. \[CONNECTOR-972\]
-   Fix Infinite loop. \[CONNECTOR-973\]
-   Fix Uncontrolled Resource Consumption. \[CONNECTOR-974\]
-   Fix Out-of-bounds write vulnerabilities. \[CONNECTOR-1007\]
-   Fix Out-of-bounds write vulnerabilities. \[CONNECTOR-1008\]
-   Fix Out-of-bounds write vulnerabilities. \[CONNECTOR-1009\]
-   Fix Out-of-bounds write vulnerabilities. \[CONNECTOR-1010\]
-   Fix Out-of-bounds write vulnerabilities. \[CONNECTOR-1011\]

---

## Connect for Event Stream Processing (ESP) 2.4.0

March 25, 2024  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### New Features

-   Make batching of ack configurable as a toggle. \[CONNECTOR-922\]

### Security

-   Fix Allocation of Resources Without Limits or Throttling. [CVE-2024-26308](https://github.com/advisories/GHSA-4265-ccf5-phj5) \[CONNECTOR-928\]
-   Fix Infinite loop. [CVE-2024-25710](https://github.com/advisories/GHSA-4g9r-vxhx-9pgx) \[CONNECTOR-929\]

---

## Connect for Event Stream Processing (ESP) 2.3.0

November 07, 2023  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### New Features

-   Add option to disable ESP health check. \[CONNECTOR-823\]

### Improvements

-   Return all destination Aerospike server error codes to XDR source cluster. \[CONNECTOR-805\]

### Security

-   Upgrade netty and gRPC for [CVE-2023-44487](https://github.com/advisories/GHSA-qppj-fm5r-hxr3). \[CONNECTOR-825\]

---

## Connect for Event Stream Processing (ESP) 2.2.1

August 09, 2023  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Security

-   Address [CVE-2023-36480](https://github.com/advisories/GHSA-jj95-55cr-9597) - upgrade to aerospike-java-client version 7.0.0. \[CONNECTOR-775\]

---

## Connect for Event Stream Processing (ESP) 2.2.0

July 21, 2023  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### New Features

-   Batching support. \[CONNECTOR-373\]
-   Batching support for inbuilt formats. \[CONNECTOR-431\]
-   JSON logging format. \[CONNECTOR-584\]
-   Bin include/exclude option in bin transformer. \[CONNECTOR-705\]

### Improvements

-   Upgrade internal dependencies. \[CONNECTOR-716\]

---

## Connect for Event Stream Processing (ESP) 2.1.1

May 17, 2023  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   The \*.deb and \*.rpm files support multiple architectures (ARM64 & AMD64).
-   The connector is Java JVM based. Install the correct JVM for the desired architecture.
-   **This connector requires Java 11 or later.**

### Improvements

-   Multi-arch container image supporting linux/arm64 and linux/amd64 platforms. \[CONNECTOR-562\]
-   Upgrade vulnerable dependencies. \[CONNECTOR-679\]

### Bug Fixes

-   Correct ESP healthcheck URL for http connectors. \[CONNECTOR-624\]

---

## Connect for Event Stream Processing (ESP) 2.1.0

January 12, 2023  |  [**Download**](https://aerospike.com/download/connector/esp/)

### Bug Fixes

-   Fix CVE-2022-3509 in ESP Outbound Connector. \[CONNECTOR-564\]
-   Fix CVE-2022-3510 in ESP Outbound Connector. \[CONNECTOR-574\]
-   Fix CVE-2022-41881 in ESP Outbound Connector. \[CONNECTOR-575\]

---

## Connect for Event Stream Processing (ESP) 2.0.0

April 04, 2022  |  [**Download**](https://aerospike.com/download/connector/esp/)

### New Features

-   Provide an option for in-order delivery of different versions of the same record. \[CONNECTOR-340\]

### Improvements

-   Performance and stability improvements. \[CONNECTOR-341\]
-   Vulnerability scanning and dependency upgrades. \[CONNECTOR-342\]
-   Single installer for HTTP and XDR 5.0 wire protocol connector. \[CONNECTOR-343\]

---

## Connect for Event Stream Processing (ESP) 1.1.0

February 04, 2022  |  [**Download**](https://aerospike.com/download/connector/esp/)

### New Features

-   Add support to plugin custom code through the Custom transformer API. \[CONNECTOR-319\]

### Improvements

-   Support Java 17 runtime. \[CONNECTOR-320\]
-   Add ESP destination config `http-success-status-codes` to specify HTTP status codes to indicate successful response. \[CONNECTOR-322\]
-   Add a routing config to skip dispatching of records to the destination. \[CONNECTOR-323\]

### Bug Fixes

-   Fix a memory leak on HTTP/2 remote stream cancel with HTTP/2 protocol. \[CONNECTOR-324\]
-   ESP does not validate TLS config on start up. \[CONNECTOR-325\]

---

## Connect for Event Stream Processing (ESP) 1.0.0

October 15, 2021  |  [**Download**](https://aerospike.com/download/connector/esp/)

-   Initial General Availability release for Aerospike Server Enterprise Edition version 5.0 and above.
-   Legacy support for versions of the Aerospike Server Enterprise Edition version 4.9 and below.
    -   If using a version prior to server 4.9, you must use the HTTP connector.
    -   WARNING: A serious flaw has been discovered for HTTP/2 in the library used by change notification in Aerospike Enterprise Editions prior to 5.0. `http-version` MUST be set to `v1` to prevent XDR and CN from being blocked.