Skip to content
Apache ZooKeeperGHSA-crhr-qqj8-rpxc

Apache ZooKeeper has improper handling of configuration values

HighCVE-2026-24308 · Published Mar 7, 2026 · updated Sep 10, 2026

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.zookeeper:zookeeper
Maven
>= 3.9.0, < 3.9.53.9.5
>= 3.8.0, < 3.8.63.8.6
Details and references

More Apache ZooKeeper advisories

All Apache ZooKeeper

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.