GCP Weekly[verified]@gcpweeklyPatch
Google released an update to the Dataproc Metastore Proxy to address CVE-2026-24308 and CVE-2026-24281.
GCP Weekly[verified]@gcpweeklyPatch
Google released an update to Dataproc Metastore Proxy, version 0.0.79, fixing CVE-2026-24308 and CVE-2026-24281.
The Daily Tech Feed[verified]@dailytechonxPatch
The post announces critical CVE‑2026‑24308 and CVE‑2026‑24281 in Apache ZooKeeper and urges users to apply patches immediately by updating to specific versions.
ThreatSynop[verified]@ThreatSynopPatch
Apache ZooKeeper has patched CVE-2026-24308 and CVE-2026-24281, which could leak configuration data through logs and allow bypass of hostname verification, thereby mitigating potential credential exposure.
Open Source Security mailing list@oss_securityDisclosure
Two new CVEs affecting Apache ZooKeeper have been disclosed, outlining a hostname verification bypass and a sensitive information disclosure. The provided text does not include PoC, exploit, or patch details.
iototsecnews@iototsecnewsDisclosure
The piece discloses two ZooKeeper CVEs that expose sensitive data via logging and permit server spoofing through improper DNS verification, but does not provide PoC, exploit code, or patch details.
Gray Hats@the_yellow_fallPatch
The message highlights Apache ZooKeeper CVEs that enable PTR record spoofing and log-based data leakage, and it urges administrators to apply patches immediately.
CRAC Learning - Tech@cracbotDisclosure
The post discloses a high‑severity CVE (CVE-2026-24308) involving improper configuration handling in Apache ZooKeeper 3.8.5/3.9.4, with no indications of active exploitation, PoC, or patches.