apache/kafka · error · SchemaException

The response is unrelated to Sasl request since its…

Error message

The response is unrelated to Sasl request since its correlation id is {} and the reserved range for Sasl request is [ {},{}]

What it means

Thrown by NetworkClient.parseResponse() inside the CorrelationIdMismatchException handler when the original request used a SASL-reserved correlation ID but the response's correlation ID falls outside the reserved SASL range. This means the response does not correspond to the SASL handshake request — it is unrelated traffic or a protocol desync, so it is rejected as a SchemaException.

Solutions

  1. Verify there is no proxy or middleware interfering with the SASL authentication channel.
  2. Ensure the broker version is compatible with the client's SASL mechanism.
  3. Check for concurrent use of the same connection for both SASL and non-SASL requests (should not happen in normal operation).
  4. Report as a broker bug if reproducible with matching client/broker versions.
Defensive patterns

Strategy: try-catch

Try / catch

try {
    NetworkClient.parseResponse(buf, header);
} catch (SchemaException e) {
    // SASL correlation mismatch: treat as auth-channel corruption
}

Prevention

When it happens

Trigger: A CorrelationIdMismatchException is caught; the request header's correlation ID is within the SASL reserved range but the response's correlation ID is NOT reserved. This happens when interleaved non-SASL responses land on a SASL channel or when correlation IDs are mismanaged.

Common situations: Authentication channel multiplexing issues, concurrent request pipelines corrupting correlation ID assignment, broker bugs in correlation ID echoing, or man-in-the-middle/proxy interference on the SASL handshake.

Related errors


AI-assisted analysis of apache/kafka@996fb4585a (2026-08-11). Data as JSON: /api/errors/086628f4c02ccb3e. Report an issue: GitHub.

Appendix: source

Thrown at clients/src/main/java/org/apache/kafka/clients/NetworkClient.java:925

     */
    private LeastLoadedNode handleEmptyNodeList() {
        if (bootstrapConfiguration == BootstrapConfiguration.DISABLED || metadataUpdater.isBootstrapped()) {
            throw new IllegalStateException("There are no nodes in the Kafka cluster");
        }

        log.debug("No nodes available yet, still in bootstrap phase");
        return new LeastLoadedNode(null, false);
    }

    public static AbstractResponse parseResponse(ByteBuffer responseBuffer, RequestHeader requestHeader) {
        try {
            return AbstractResponse.parseResponse(responseBuffer, requestHeader);
        } catch (BufferUnderflowException e) {
            throw new SchemaException("Buffer underflow while parsing response for request with header " + requestHeader, e);
        } catch (CorrelationIdMismatchException e) {
            if (SaslClientAuthenticator.isReserved(requestHeader.correlationId())
                && !SaslClientAuthenticator.isReserved(e.responseCorrelationId()))
                throw new SchemaException("The response is unrelated to Sasl request since its correlation id is "
                    + e.responseCorrelationId() + " and the reserved range for Sasl request is [ "
                    + SaslClientAuthenticator.MIN_RESERVED_CORRELATION_ID + ","
                    + SaslClientAuthenticator.MAX_RESERVED_CORRELATION_ID + "]");
            else {
                throw e;
            }
        }
    }

    /**
     * Post process disconnection of a node
     *
     * @param responses The list of responses to update
     * @param nodeId Id of the node to be disconnected
     * @param now The current time
     * @param disconnectState The state of the disconnected channel
     */
    private void processDisconnection(List<ClientResponse> responses,

View on GitHub (pinned to 996fb4585a)