Apache ZooKeeper security advisories
9 advisories · 2 critical or high in 12 months · latest Mar 7
9 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 7 | Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager CVE-2026-24281High7.4fixed in 3.8.6, 3.9.5 | High7.4 | 3.8.6, 3.9.5 |
| Mar 7 | Apache ZooKeeper has improper handling of configuration values CVE-2026-24308Highfixed in 3.8.6, 3.9.5 | High | 3.8.6, 3.9.5 |
| Sep 242025 | Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands CVE-2025-58457Medium4.3fixed in 3.9.4 | Medium4.3 | 3.9.4 |
| Nov 72024 | Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server CVE-2024-51504Highfixed in 3.9.3 | High | 3.9.3 |
| Mar 152024 | Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling CVE-2024-23944Medium5.3fixed in 3.8.4, 3.9.2 | Medium5.3 | 3.8.4, 3.9.2 |
| Oct 112023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper CVE-2023-44981Critical9.1fixed in 3.7.2, 3.8.3, 3.9.1 | Critical9.1 | 3.7.2, 3.8.3, 3.9.1 |
| May 132022 | Uncontrolled Resource Consumption in Apache ZooKeeper CVE-2017-5637High7.5fixed in 3.4.10, 3.5.3 | High7.5 | 3.4.10, 3.5.3 |
| May 132022 | Missing Authorization in Apache ZooKeeper CVE-2018-8012High7.5fixed in 3.4.10, 3.5.4-beta | High7.5 | 3.4.10, 3.5.4-beta |
| May 292019 | Access control bypass in Apache ZooKeeper CVE-2019-0201Medium5.9fixed in 3.4.14, 3.5.5 | Medium5.9 | 3.4.14, 3.5.5 |
About Apache ZooKeeper
Coordination for distributed systems.
Packages watched: org.apache.zookeeper:zookeeper (Maven).