Skip to content

Apache ZooKeeper security advisories

9 advisories · 2 critical or high in 12 months · latest Mar 7

9 advisories

DateAdvisory
Mar 7Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
CVE-2026-24281High7.4fixed in 3.8.6, 3.9.5
Mar 7Apache ZooKeeper has improper handling of configuration values
CVE-2026-24308Highfixed in 3.8.6, 3.9.5
Sep 242025Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
CVE-2025-58457Medium4.3fixed in 3.9.4
Nov 72024Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2024-51504Highfixed in 3.9.3
Mar 152024Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
CVE-2024-23944Medium5.3fixed in 3.8.4, 3.9.2
Oct 112023Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
CVE-2023-44981Critical9.1fixed in 3.7.2, 3.8.3, 3.9.1
May 132022Uncontrolled Resource Consumption in Apache ZooKeeper
CVE-2017-5637High7.5fixed in 3.4.10, 3.5.3
May 132022Missing Authorization in Apache ZooKeeper
CVE-2018-8012High7.5fixed in 3.4.10, 3.5.4-beta
May 292019Access control bypass in Apache ZooKeeper
CVE-2019-0201Medium5.9fixed in 3.4.14, 3.5.5
About Apache ZooKeeper

Coordination for distributed systems.

Packages watched: org.apache.zookeeper:zookeeper (Maven).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.