Critical Bypasses and Secret Leaks Patched in Apache ZooKeeper
ID: 98f4e127-d0be-544e-8ebd-7a26a0598ca5
STIX ID: report--98f4e127-d0be-544e-8ebd-7a26a0598ca5
Feed Name: securityonline.info
Apache ZooKeeper released urgent patches addressing two important vulnerabilities: CVE-2026-24281 in ZKTrustManager where failed IP-SAN validation falls back to reverse-DNS (PTR) allowing an attacker who can spoof PTR records and present a trusted certificate to impersonate servers/clients, and CVE-2026-24308 in ZKConfig where sensitive client configuration (credentials/private keys) are logged at INFO level and may be exposed. The flaws affect ZooKeeper 3.9.0–3.9.4 and 3.8.0–3.8.5 and are fixed in 3.9.5 and 3.8.6; administrators are urged to upgrade and consider disabling reverse DNS lookups during hostname verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
