{"record":{"id":"086628f4c02ccb3e","repo":"apache/kafka","slug":"the-response-is-unrelated-to-sasl-request-since-it","errorCode":null,"errorMessage":"The response is unrelated to Sasl request since its correlation id is {} and the reserved range for Sasl request is [ {},{}]","messagePattern":"The response is unrelated to Sasl request since its correlation id is (.+?) and the reserved range for Sasl request is \\[ (.+?),(.+?)\\]","errorType":"exception","errorClass":"SchemaException","httpStatus":null,"severity":"error","filePath":"clients/src/main/java/org/apache/kafka/clients/NetworkClient.java","lineNumber":925,"sourceCode":"     */\n    private LeastLoadedNode handleEmptyNodeList() {\n        if (bootstrapConfiguration == BootstrapConfiguration.DISABLED || metadataUpdater.isBootstrapped()) {\n            throw new IllegalStateException(\"There are no nodes in the Kafka cluster\");\n        }\n\n        log.debug(\"No nodes available yet, still in bootstrap phase\");\n        return new LeastLoadedNode(null, false);\n    }\n\n    public static AbstractResponse parseResponse(ByteBuffer responseBuffer, RequestHeader requestHeader) {\n        try {\n            return AbstractResponse.parseResponse(responseBuffer, requestHeader);\n        } catch (BufferUnderflowException e) {\n            throw new SchemaException(\"Buffer underflow while parsing response for request with header \" + requestHeader, e);\n        } catch (CorrelationIdMismatchException e) {\n            if (SaslClientAuthenticator.isReserved(requestHeader.correlationId())\n                && !SaslClientAuthenticator.isReserved(e.responseCorrelationId()))\n                throw new SchemaException(\"The response is unrelated to Sasl request since its correlation id is \"\n                    + e.responseCorrelationId() + \" and the reserved range for Sasl request is [ \"\n                    + SaslClientAuthenticator.MIN_RESERVED_CORRELATION_ID + \",\"\n                    + SaslClientAuthenticator.MAX_RESERVED_CORRELATION_ID + \"]\");\n            else {\n                throw e;\n            }\n        }\n    }\n\n    /**\n     * Post process disconnection of a node\n     *\n     * @param responses The list of responses to update\n     * @param nodeId Id of the node to be disconnected\n     * @param now The current time\n     * @param disconnectState The state of the disconnected channel\n     */\n    private void processDisconnection(List<ClientResponse> responses,","sourceCodeStart":907,"sourceCodeEnd":943,"githubUrl":"https://github.com/apache/kafka/blob/996fb4585aa1bcc8980b0e1b8d6b168b986cd979/clients/src/main/java/org/apache/kafka/clients/NetworkClient.java#L907-L943","documentation":"Thrown by NetworkClient.parseResponse() inside the CorrelationIdMismatchException handler when the original request used a SASL-reserved correlation ID but the response's correlation ID falls outside the reserved SASL range. This means the response does not correspond to the SASL handshake request — it is unrelated traffic or a protocol desync, so it is rejected as a SchemaException.","triggerScenarios":"A CorrelationIdMismatchException is caught; the request header's correlation ID is within the SASL reserved range but the response's correlation ID is NOT reserved. This happens when interleaved non-SASL responses land on a SASL channel or when correlation IDs are mismanaged.","commonSituations":"Authentication channel multiplexing issues, concurrent request pipelines corrupting correlation ID assignment, broker bugs in correlation ID echoing, or man-in-the-middle/proxy interference on the SASL handshake.","solutions":["Verify there is no proxy or middleware interfering with the SASL authentication channel.","Ensure the broker version is compatible with the client's SASL mechanism.","Check for concurrent use of the same connection for both SASL and non-SASL requests (should not happen in normal operation).","Report as a broker bug if reproducible with matching client/broker versions."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n    NetworkClient.parseResponse(buf, header);\n} catch (SchemaException e) {\n    // SASL correlation mismatch: treat as auth-channel corruption\n}","preventionTips":["Ensure no middleware interferes with the SASL handshake channel.","Use matching SASL mechanism config on client and broker.","Watch for this error after security-config changes."],"tags":["sasl","authentication","protocol"],"backgroundTag":null,"analyzedSha":"996fb4585aa1bcc8980b0e1b8d6b168b986cd979","analyzedAt":"2026-08-11T22:03:28.655Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}