Apache / Zookeeper
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84501 | Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-84439 | Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-79993 | Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-59969 | Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-59739 | Apache ZooKeeper: Information disclosure via SetWatches reconnect replay | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-24308 | Apache ZooKeeper: Sensitive information disclosure in client configuration handling | HIGH | 8.7 | Mar 7, 2026 |
| CVE-2026-24281 | Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager | HIGH | 7.4 | Mar 7, 2026 |
| CVE-2025-58457 | Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands | MEDIUM | 4.3 | Sep 24, 2025 |
| CVE-2024-51504 | Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server | HIGH | 8.8 | Nov 7, 2024 |
| CVE-2024-23944 | Apache ZooKeeper: Information disclosure in persistent watcher handling | MEDIUM | 6.6 | Mar 15, 2024 |
| CVE-2023-44981 | Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication | CRITICAL | 9.1 | Oct 11, 2023 |
| CVE-2021-21295 | Possible request smuggling in HTTP/2 due missing validation | MEDIUM | 5.9 | Mar 9, 2021 |
| CVE-2019-0201 | zookeeper: Information disclosure in Apache ZooKeeper | MEDIUM | 5.9 | May 23, 2019 |
| CVE-2018-8012 | zookeeper: No authentication or authorization is enforced when a server joins a quorum | HIGH | 7.5 | May 21, 2018 |
| CVE-2017-5637 | zookeeper: Incorrect input validation with wchp/wchc four letter words | HIGH | 7.5 | Oct 10, 2017 |
| CVE-2016-5017 | zookeeper: Buffer overflow vulnerability in C cli shell | HIGH | 8.1 | Sep 21, 2016 |
Showing 1 to 16 of 16 CVEs