logo

Critical Bypasses and Secret Leaks Patched in Apache ZooKeeper

ID: 98f4e127-d0be-544e-8ebd-7a26a0598ca5

STIX ID: report--98f4e127-d0be-544e-8ebd-7a26a0598ca5

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache ZooKeeper released urgent patches addressing two important vulnerabilities: CVE-2026-24281 in ZKTrustManager where failed IP-SAN validation falls back to reverse-DNS (PTR) allowing an attacker who can spoof PTR records and present a trusted certificate to impersonate servers/clients, and CVE-2026-24308 in ZKConfig where sensitive client configuration (credentials/private keys) are logged at INFO level and may be exposed. The flaws affect ZooKeeper 3.9.0–3.9.4 and 3.8.0–3.8.5 and are fixed in 3.9.5 and 3.8.6; administrators are urged to upgrade and consider disabling reverse DNS lookups during hostname verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.