VendorsApachezookeeperany version
Vulnerabilities

Apache Zookeeper any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-44981
Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication
Published 2023-10-11 · Modified
9.1EPSS 0.017
CVE-2024-51504
Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
Published 2024-11-07 · Analyzed
9.1EPSS 0.009
CVE-2016-5017
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Published 2016-09-21 · Modified
8.1EPSS 0.079
CVE-2018-8012
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
Published 2018-05-21 · Modified
7.5EPSS 0.085
CVE-2026-24308
Apache ZooKeeper: Sensitive information disclosure in client configuration handling
Published 2026-03-07 · Modified
7.5EPSS 0.012
CVE-2026-79993
Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
Published 2026-09-16 · Analyzed
7.5EPSS 0.006
CVE-2026-59739
Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
Published 2026-09-16 · Analyzed
7.5EPSS 0.006
CVE-2026-59969
Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Published 2026-09-16 · Analyzed
7.5EPSS 0.004
CVE-2026-24281
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Published 2026-03-07 · Modified
7.4EPSS 0.006
CVE-2019-0201
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Published 2019-05-23 · Modified
5.9EPSS 0.097
CVE-2026-84439
Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Published 2026-09-16 · Analyzed
5.3EPSS 0.008
CVE-2026-84501
Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider
Published 2026-09-16 · Analyzed
5.3EPSS 0.008
CVE-2024-23944
Apache ZooKeeper: Information disclosure in persistent watcher handling
Published 2024-03-15 · Modified
5.3EPSS 0.002
CVE-2025-58457
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Published 2025-09-24 · Modified
4.3EPSS 0.003