Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2026-84501

Medium priority
Needs evaluation

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84439

Medium priority
Needs evaluation

When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-79993

Medium priority
Needs evaluation

The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59969

Medium priority
Needs evaluation

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true,...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59739

Medium priority
Needs evaluation

Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24308

Medium priority
Needs evaluation

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24281

Medium priority
Needs evaluation

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-58457

Medium priority
Needs evaluation

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are recommended to...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-51504

Medium priority
Vulnerable

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Not affected Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2024-23944

Medium priority
Vulnerable

Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker...

1 affected package

zookeeper

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zookeeper Not affected Vulnerable Not affected Not affected Not affected
Show less packages