apache/kafka · error · SchemaException
The response is unrelated to Sasl request since its…
Error message
The response is unrelated to Sasl request since its correlation id is {} and the reserved range for Sasl request is [ {},{}] What it means
Thrown by NetworkClient.parseResponse() inside the CorrelationIdMismatchException handler when the original request used a SASL-reserved correlation ID but the response's correlation ID falls outside the reserved SASL range. This means the response does not correspond to the SASL handshake request — it is unrelated traffic or a protocol desync, so it is rejected as a SchemaException.
Solutions
- Verify there is no proxy or middleware interfering with the SASL authentication channel.
- Ensure the broker version is compatible with the client's SASL mechanism.
- Check for concurrent use of the same connection for both SASL and non-SASL requests (should not happen in normal operation).
- Report as a broker bug if reproducible with matching client/broker versions.
Defensive patterns
Strategy: try-catch
Try / catch
try {
NetworkClient.parseResponse(buf, header);
} catch (SchemaException e) {
// SASL correlation mismatch: treat as auth-channel corruption
} Prevention
- Ensure no middleware interferes with the SASL handshake channel.
- Use matching SASL mechanism config on client and broker.
- Watch for this error after security-config changes.
When it happens
Trigger: A CorrelationIdMismatchException is caught; the request header's correlation ID is within the SASL reserved range but the response's correlation ID is NOT reserved. This happens when interleaved non-SASL responses land on a SASL channel or when correlation IDs are mismanaged.
Common situations: Authentication channel multiplexing issues, concurrent request pipelines corrupting correlation ID assignment, broker bugs in correlation ID echoing, or man-in-the-middle/proxy interference on the SASL handshake.
Related errors
- Buffer underflow while parsing response for request with…
- Connection to failed.
- Unexpected config source
- When the security.protocol configuration enables SASL…
AI-assisted analysis of apache/kafka@996fb4585a (2026-08-11).
Data as JSON: /api/errors/086628f4c02ccb3e.
Report an issue: GitHub.
Appendix: source
Thrown at clients/src/main/java/org/apache/kafka/clients/NetworkClient.java:925
*/
private LeastLoadedNode handleEmptyNodeList() {
if (bootstrapConfiguration == BootstrapConfiguration.DISABLED || metadataUpdater.isBootstrapped()) {
throw new IllegalStateException("There are no nodes in the Kafka cluster");
}
log.debug("No nodes available yet, still in bootstrap phase");
return new LeastLoadedNode(null, false);
}
public static AbstractResponse parseResponse(ByteBuffer responseBuffer, RequestHeader requestHeader) {
try {
return AbstractResponse.parseResponse(responseBuffer, requestHeader);
} catch (BufferUnderflowException e) {
throw new SchemaException("Buffer underflow while parsing response for request with header " + requestHeader, e);
} catch (CorrelationIdMismatchException e) {
if (SaslClientAuthenticator.isReserved(requestHeader.correlationId())
&& !SaslClientAuthenticator.isReserved(e.responseCorrelationId()))
throw new SchemaException("The response is unrelated to Sasl request since its correlation id is "
+ e.responseCorrelationId() + " and the reserved range for Sasl request is [ "
+ SaslClientAuthenticator.MIN_RESERVED_CORRELATION_ID + ","
+ SaslClientAuthenticator.MAX_RESERVED_CORRELATION_ID + "]");
else {
throw e;
}
}
}
/**
* Post process disconnection of a node
*
* @param responses The list of responses to update
* @param nodeId Id of the node to be disconnected
* @param now The current time
* @param disconnectState The state of the disconnected channel
*/
private void processDisconnection(List<ClientResponse> responses,View on GitHub (pinned to 996fb4585a)