CVE-2026-24281Patch(apache / zookeeper)

LOWCVSS 7.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache zookeeper systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-350

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zookeeper

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-03-09); latest day: 2
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
zookeeper

Deep dive

Activity timeline12 mentions / 6d
01234Mentions · 2026-03-07: 3Mentions · 2026-03-09: 4Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-04-03: 2Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-04-03: 2Technical Details · 2026-03-07: 3Technical Details · 2026-03-09: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 103-0703-0903-1103-1203-1604-03
Signal classification3 categories
Patch
650.0%
Disclosure
541.7%
General
18.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-073
Disclosure3
2026-03-094
Disclosure1General1Patch2
2026-03-111
Patch1
2026-03-121
Disclosure1
2026-03-161
Patch1
2026-04-032
Patch2
Full discourse12 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-24281: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager https://www.openwall.com/lists/oss-security/2026/03/07/4 CVE-2026-24308: Apache ZooKeeper: Sensitive information disclosure in client configuration handling https://www.openwall.com/lists/oss-security/2026/03/07/5

    Post summary

    Two Apache ZooKeeper vulnerabilities were disclosed: CVE‑2026‑24281, a hostname verification bypass via Reverse‑DNS fallback in ZKTrustManager, and CVE‑2026‑24308, a sensitive information disclosure in client configuration handling.

    00041326
    4.4K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    Dataproc update on April 2, 2026 https://docs.cloud.google.com/dataproc/docs/release-notes#April_02_2026 #googlecloud Upgraded Dataproc Metastore Proxy to v0.0.79 to fix CVEs. Fixed CVEs CVE-2026-24308 and CVE-2026-24281 1/2

    Post summary

    Google Cloud released Dataproc Metastore Proxy v0.0.79 on April 2, 2026, patching CVE‑2026‑24308 and CVE‑2026‑24281. No PoC, exploit, or active exploitation details are provided.

    1100084
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    Dataproc Serverless update on April 2, 2026 https://docs.cloud.google.com/dataproc-serverless/docs/release-notes/#April_02_2026 #googlecloud Upgraded Dataproc Metastore Proxy to v0.0.79 to fix CVEs. Fixed CVEs CVE-2026-24308 and CVE-2026-24281 1/2

    Post summary

    The April 2, 2026 Dataproc Serverless update upgrades the Metastore Proxy to v0.0.79, addressing CVE-2026-24308 and CVE-2026-24281, as noted in the Google Cloud release notes; no proof of concept, exploit, or detailed technical vulnerability information is provided.

    1000075
    1.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache ZooKeeper の脆弱性 CVE-2026-24308/24281 が FIX:機密ログの漏洩とサーバなりすましの恐れ https://iototsecnews.jp/2026/03/09/apache-zookeeper-flaw-exposes-sensitive-data-to-attackers/ 今回の脆弱性は、システムの土台を支える設定管理や検証の、不適切な仕組みに起因するものです。1 件目の CVE-2026-24308 は、本来は秘匿されるべき認証情報が INFO レベルのログとして出力されてしまう、コンフィグ処理の不備が原因です。開発時の確認用ログが、本番環境でも残ってしまったような状態といえます。 2件目の CVE-2026-24281 は、接続先の正当性を確かめるホスト名検証において、安全性の低い逆 DNS (PTR) ルックアップへ、自動的に切り替えが生じてしまう欠陥です。この経路を悪用する攻撃者は、偽のサーバになりすますことが可能になります。ご利用のチームは、ご注意ください。 #Apache #CVE202624281 #CVE202624308 #Vulnerability #ZooKeeper

    Post summary

    The article announces that Apache ZooKeeper’s CVE‑2026‑24308 and CVE‑2026‑24281 vulnerabilities have been fixed, detailing how the bugs caused confidential log exposure and server impersonation via improper config logging and insecure reverse‑DNS validation, respectively.

    01000109
    484 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache ZooKeeper vulnerabilities (CVE-2026-24281, CVE-2026-24308) allow PTR record spoofing and sensitive data leaks in logs. Update clusters immediately. #ApacheZooKeeper #CyberSecurity #InfoSec #Vulnerability #PatchAlert #DataLeak #ThreatIntel #AppSec https://securityonline.info/critical-bypasses-and-secret-leaks-patched-in-apache-zookeeper/ https://t.co/iIu78yQXGT

    Post summary

    The post announces CVEs 2026-24281 and 2026-24308 in Apache ZooKeeper that enable PTR record spoofing and logs-sensitive data leaks, and it urges immediate cluster updates.

    00010313
    10.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24281 (CVSS:7.4, HIGH) is Modified. Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a..https://nvd.nist.gov/vuln/detail/CVE-2026-24281 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses a modified CVE‑2026‑24281, noting that Apache ZooKeeper’s ZKTrustManager may fall back to reverse DNS for hostname verification when IP SAN validation fails, with a CVSS score of 7.4 (HIGH).

    0000027
    172 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Alert: Critical vulnerabilities CVE-2026-24308 & CVE-2026-24281 found in Apache ZooKeeper. Immediate patching to versions 3.8.6 or 3.9.5 is essential. Link: https://thedailytechfeed.com/critical-flaws-in-apache-zookeeper-threaten-data-security-urgent-patches-released/ #Vulnerability #Security #Patch #Update #Apache #ZooKeeper #Data #Protection #Cyber #Threat #CVE #Network #Software #Tech #IT #Bugs #Fix #Urgent #Risk #System

    Post summary

    The post alerts about CVE-2026-24308 and CVE-2026-24281 in Apache ZooKeeper, urging immediate patching to versions 3.8.6 or 3.9.5, and links to a news article.

    000005
    260 followersView on X
  • Autumn Good@autumn_good_35
    General

    CVE-2026-24308: Sensitive information disclosure in client configuration handling CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager ZooKeeper Security https://zookeeper.apache.org/security.html

    Post summary

    The post lists two CVE identifiers with descriptive titles but lacks any details on Proof‑of‑Concepts, exploitation, or mitigation steps.

    00000421
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Apache ZooKeeper flaws expose secrets and weaken server identity checks Apache ZooKeeper patched two important flaws—CVE-2026-24308 and CVE-2026-24281—that can leak sensitive configuration data through logs and allow hostname verification bypass via reverse DNS fallback, raising the risk of credential exposure and man-in-the-middle scenarios. This matters because ZooKeeper is widely embedded in distributed environments, so weak logging hygiene or trust validation can cascade into broader infrastructure compromise. 🎯 Target: Global/Organizations Using Apache ZooKeeper #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/apache-zookeeper-vulnerability/

    Post summary

    The article reports that Apache ZooKeeper has patched two critical CVEs that could leak config data and bypass hostname verification, but does not mention active exploitation, PoC, or false positives.

    0000057
    273 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24281 Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR rec… https://www.cve.org/CVERecord?id=CVE-2026-24281

    Post summary

    The tweet announces CVE-2026-24281 and provides a concise technical description of a hostname verification flaw in Apache ZooKeeper, without indicating any PoC, exploit, patch, or active exploitation.

    00000127
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-24281 - Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager Intel Report: https://ift.tt/TucValN

    Post summary

    The advisory announces CVE‑2026‑24281, outlining a hostname verification bypass in Apache ZooKeeper caused by Reverse‑DNS fallback, but no exploit, patch, or active use is reported.

    0000036
    344 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24281 Hostname Verification Bypass in Apache ZooKeeper ZKTrustManager via PTR Record Spoofing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24281

    Post summary

    A brief mention of CVE-2026-24281, noting a hostname verification bypass via PTR spoofing in ZooKeeper, with no further technical details or actionable information.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachezookeeper---

Explore more