Known Vulnerabilities for Apache ZooKeeper by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache ZooKeeper" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84501 json | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted ... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-84439 json | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apa... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-84179 json | Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82434 json | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82433 json | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorizati... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82426 json | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-si... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-79993 json | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticate... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-59969 json | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookee... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-59739 json | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discove... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-24308 json | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker... | Not Provided | 2026-03-07 | 2026-07-15 |