Apache ZooKeeperGHSA-crhr-qqj8-rpxc
Apache ZooKeeper has improper handling of configuration values
HighCVE-2026-24308 · Published Mar 7, 2026 · updated Sep 10, 2026
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.zookeeper:zookeeper Maven | >= 3.9.0, < 3.9.5 | 3.9.5 |
| >= 3.8.0, < 3.8.6 | 3.8.6 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-zookeeper-2026-24308, CVE-2026-24308
More Apache ZooKeeper advisories
All Apache ZooKeeper| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 7 | Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager | High7.4 | 3.8.6+1 more |
| Sep 242025 | Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands | Medium4.3 | 3.9.4 |
| Nov 72024 | Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server | High | 3.9.3 |
| Mar 152024 | Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling | Medium5.3 | 3.8.4+1 more |
| Oct 112023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper | Critical9.1 | 3.7.2+2 more |
| May 132022 | Uncontrolled Resource Consumption in Apache ZooKeeper | High7.5 | 3.4.10+1 more |