GCP Weekly[verified]@gcpweeklyPatch
Google Cloud released Dataproc Metastore Proxy v0.0.79 on April 2, 2026, patching CVE‑2026‑24308 and CVE‑2026‑24281. No PoC, exploit, or active exploitation details are provided.
GCP Weekly[verified]@gcpweeklyPatch
The April 2, 2026 Dataproc Serverless update upgrades the Metastore Proxy to v0.0.79, addressing CVE-2026-24308 and CVE-2026-24281, as noted in the Google Cloud release notes; no proof of concept, exploit, or detailed technical vulnerability information is provided.
The Daily Tech Feed[verified]@dailytechonxPatch
The post alerts about CVE-2026-24308 and CVE-2026-24281 in Apache ZooKeeper, urging immediate patching to versions 3.8.6 or 3.9.5, and links to a news article.
ThreatSynop[verified]@ThreatSynopPatch
The article reports that Apache ZooKeeper has patched two critical CVEs that could leak config data and bypass hostname verification, but does not mention active exploitation, PoC, or false positives.
Open Source Security mailing list@oss_securityDisclosure
Two Apache ZooKeeper vulnerabilities were disclosed: CVE‑2026‑24281, a hostname verification bypass via Reverse‑DNS fallback in ZKTrustManager, and CVE‑2026‑24308, a sensitive information disclosure in client configuration handling.
iototsecnews@iototsecnewsPatch
The article announces that Apache ZooKeeper’s CVE‑2026‑24308 and CVE‑2026‑24281 vulnerabilities have been fixed, detailing how the bugs caused confidential log exposure and server impersonation via improper config logging and insecure reverse‑DNS validation, respectively.
Gray Hats@the_yellow_fallPatch
The post announces CVEs 2026-24281 and 2026-24308 in Apache ZooKeeper that enable PTR record spoofing and logs-sensitive data leaks, and it urges immediate cluster updates.
CRAC Learning - Tech@cracbotDisclosure
The post discloses a modified CVE‑2026‑24281, noting that Apache ZooKeeper’s ZKTrustManager may fall back to reverse DNS for hostname verification when IP SAN validation fails, with a CVSS score of 7.4 (HIGH).