Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache ZooKeeper — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Apache ZooKeeper, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Apache ZooKeeper, a distributed coordination service developed by the Apache Software Foundation. It collects known security flaws categorized by common weakness types such as authentication bypass, denial of service, and deserialization issues. The dataset covers advisories published from 2011 through the current reporting period. Users can track the vendor’s published security updates, analyze the prevalence of specific weakness classes, and review the complete vulnerability history of the product. The aggregation allows security teams to identify recurring patterns in ZooKeeper’s threat landscape without manually parsing individual vendor announcements or third-party databases. Each entry links directly to the relevant vendor advisory or external reference, enabling detailed investigation into the specific technical cause and impact of each defect. The collection supports risk assessment by highlighting which components or versions have experienced repeated exploitation. This structured overview facilitates planning for patch management and security hardening for infrastructure relying on ZooKeeper.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-84501 Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider CWE-117 - - 2026-09-16
CVE-2026-84439 Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources CWE-117 - - 2026-09-16
CVE-2026-79993 Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode CWE-862 - - 2026-09-16
CVE-2026-59969 Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode CWE-297 - - 2026-09-16
CVE-2026-59739 Apache ZooKeeper: Information disclosure via SetWatches reconnect replay CWE-862 - - 2026-09-16
CVE-2026-24308 Apache ZooKeeper: Sensitive information disclosure in client configuration handling CWE-532 7.5 - 2026-03-07
CVE-2026-24281 Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager CWE-350 7.4 - 2026-03-07
CVE-2025-58457 Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands CWE-280 8.8AI High AI 2025-09-24
CVE-2024-51504 Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server CWE-290 9.1AI Critical AI 2024-11-07
CVE-2024-23944 Apache ZooKeeper: Information disclosure in persistent watcher handling CWE-862 5.3 - 2024-03-15
CVE-2023-44981 Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication CWE-639 9.1 - 2023-10-11
CVE-2019-0201 Apache Zookeeper 授权问题漏洞 5.9 - 2019-05-23
CVE-2018-8012 Apache Zookeeper 访问控制错误漏洞 7.5 - 2018-05-21
CVE-2017-5637 Apache Zookeeper 安全漏洞 7.5 - 2017-10-10

All 14 known CVE vulnerabilities affecting Apache ZooKeeper with full Chinese analysis, references, and POCs where available.