In confluent-kafka-go v2.10.0, vulnerability was identified in the indirect dependency **golang-jwt/jwt/v5** . Please find this [link](https://github.com/advisories/GHSA-mh63-6h87-95cp) for more details. Issue identified in : github.com/golang-jwt/jwt/v5 >= 5.0.0-rc.1, < 5.2.2 Recommended fix : github.com/golang-jwt/jwt/v5 5.2.2