Back to blog

// OSSeva Blog

Security

ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9

Matt Reynolds7 min read

The short answer

Apache ZooKeeper publishes its own advisories on the ZooKeeper security page. Thirteen CVEs have been issued since 2018, seven of them in 2026. Only two release lines still get fixes: 3.9 (current, latest 3.9.6) and 3.8 (stable, latest 3.8.7), both released on 15 September 2026. Lines 3.4 to 3.7 are end of life, so a vulnerability in Apache ZooKeeper found today is never patched there. ZooKeeper 3.10 is being prepared but is not released.

Release lines and end-of-life dates

LineLast releaseEnd of life
3.43.4.14 (2 Apr 2019)1 Jun 2020
3.53.5.10 (4 Jun 2022)1 Jun 2022
3.63.6.4 (30 Dec 2022)30 Dec 2022
3.73.7.2 (9 Oct 2023)2 Feb 2024
3.83.8.7 (15 Sep 2026)None announced
3.93.9.6 (15 Sep 2026)None announced

ZooKeeper's own CVEs, with affected and fixed versions

Scores are the CVSS 3.1 base scores shown on NVD. Where NVD has not scored a CVE, the score is the one CISA added as an ADP.

CVECVSSAffectedFixed inWhat it is
CVE-2018-80127.5before 3.4.10; 3.5.0-alpha to 3.5.3-beta3.4.10, 3.5.4-betaNo authentication for servers joining the quorum
CVE-2019-02015.9up to 3.4.13; 3.5.0-alpha to 3.5.4-beta3.4.14, 3.5.5getACL() leaks unsalted digest hashes
CVE-2023-449819.1all of 3.4 to 3.6; 3.7.0-3.7.1; 3.8.0-3.8.2; 3.9.03.7.2, 3.8.3, 3.9.1SASL quorum peer authentication bypass
CVE-2024-239445.33.6.0-3.7.2; 3.8.0-3.8.3; 3.9.0-3.9.13.8.4, 3.9.2Persistent watcher leaks child paths without an ACL check
CVE-2024-515049.13.9.0-3.9.23.9.3AdminServer IP authentication bypass via X-Forwarded-For
CVE-2025-584574.33.9.0-3.9.33.9.4AdminServer snapshot and restore with weak permission checks
CVE-2026-242817.43.8.0-3.8.5; 3.9.0-3.9.43.8.6, 3.9.5ZKTrustManager hostname verification falls back to reverse DNS (PTR)
CVE-2026-243087.53.8.0-3.8.5; 3.9.0-3.9.43.8.6, 3.9.5Improper handling of configuration values: sensitive client config logged at INFO
CVE-2026-597397.53.8.0-3.8.6; 3.9.0-3.9.53.8.7, 3.9.6SetWatches replay skips the ACL check (incomplete fix of CVE-2024-23944)
CVE-2026-599697.53.8.0-3.8.6; 3.9.0-3.9.53.8.7, 3.9.6Quorum TLS in FIPS mode skips hostname verification
CVE-2026-799937.53.8.0-3.8.6; 3.9.0-3.9.53.8.7, 3.9.6deleteContainer skips session and ACL checks
CVE-2026-844395.33.8.0-3.8.6; 3.9.0-3.9.53.8.7, 3.9.6Audit-log field injection
CVE-2026-845015.33.8.0-3.8.6; 3.9.0-3.9.53.8.7, 3.9.6Operational-log forgery via newlines

CVE-2026-24281 lets an attacker who controls PTR records impersonate a ZooKeeper server or client. CVE-2026-24308 is an information disclosure in client log files. For both, users are recommended to upgrade to version 3.8.6 or 3.9.5. The CVE-2026-24281 fix adds a new configuration option to disable reverse DNS lookup in the client and quorum protocols; an attacker also needs a certificate the ZKTrustManager trusts, which makes it harder to exploit.

End-of-life lines with no fix

  • 3.4, 3.5 and 3.6: CVE-2023-44981 has no fix. 3.6 also carries CVE-2024-23944.
  • 3.7: 3.7.2 fixes CVE-2023-44981 but not CVE-2024-23944, which affects every 3.7 release.
  • The 2026 CVEs: the advisories list only 3.8 and 3.9, because the project does not assess end-of-life lines. They do not say whether 3.4 to 3.7 are affected, so treat that as unknown, not as clean.

CVE-2023-44981 matters only where SASL quorum peer authentication is on (quorum.auth.enableSasl=true). The advisory says it "is not enabled by default" and that firewalling the election and quorum ports mitigates it. An attacker who reaches those ports on a vulnerable ensemble can join it and push counterfeit changes to the leader.

Bundled dependencies: log4j, Jetty and Netty

ZooKeeper releaseLoggingJettyNetty
3.4.14log4j 1.2.17none3.10.6
3.5.5 to 3.5.9log4j 1.2.179.4.17 to 9.4.354.1.29 to 4.1.50
3.5.10reload4j 1.2.209.4.464.1.77
3.6.3log4j 1.2.179.4.394.1.63
3.6.4reload4j 1.2.249.4.494.1.86
3.7.0log4j 1.2.179.4.384.1.59
3.8.7, 3.9.6logback 1.3.159.4.584.1.137
  • log4j 1.2.17 ships in every 3.4.x, 3.5.x up to 3.5.9, 3.6.x up to 3.6.3 and 3.7.0. Scanners report CVE-2019-17571, CVE-2021-4104, CVE-2022-23302, CVE-2022-23305 and CVE-2022-23307 against it. Each needs a specific appender or component (SocketServer, JMSAppender, JMSSink, JDBCAppender, Chainsaw). ZooKeeper's shipped log4j.properties (checked for 3.6.3) defines only console and file appenders, so these are compliance findings unless you configured one of them.
  • Jetty 9 runs the AdminServer from 3.5 onward. Jetty 9 reached end of life in January 2025, yet 3.8.7 and 3.9.6 still bundle 9.4.58. Only the unreleased 3.10 moves to Jetty 12.
  • Netty 4.1.29 to 4.1.63 falls inside the range for CVE-2021-37136 and CVE-2021-37137 (decoder denial of service). Whether ZooKeeper reaches those codecs is not established.

CISA KEV

No ZooKeeper CVE is in the CISA Known Exploited Vulnerabilities catalogue, and no log4j 1.x CVE either. The Log4Shell CVEs in KEV are Log4j 2, which ZooKeeper never shipped.

How to check your ZooKeeper version

Ask each ZooKeeper server directly, or read the jar on disk:

echo srvr | nc zk1.example.internal 2181     # first line: Zookeeper version
curl http://zk1.example.internal:8080/commands/srvr   # AdminServer, 3.5+
ls /opt/product/lib | grep -i zookeeper       # zookeeper-3.x.y.jar

From 3.5.3, srvr is the only four-letter word enabled by default. For ZooKeeper embedded in another product, the jar filename is the answer. Solr 8.11.4 ships 3.6.2, Solr 9.0.0 ships 3.7.0, CDH 5 and 6 ship 3.4.5, and CDP 7.1.6 to 7.1.8 ship 3.5.5. The ZooKeeper hub lists the version bundled by each product.

Your options

  1. Upgrade to 3.8.7 or 3.9.6 where you run the ensemble yourself.
  2. Reduce exposure: firewall the quorum and election ports, keep the client port and AdminServer off untrusted networks.
  3. Patch in place: a patched build of your line, when the product that embeds ZooKeeper cannot move.
  4. Attest: document CVEs that do not apply to your configuration.
  5. Migrate the product to Raft-based coordination, product by product (ZooKeeper vs etcd, Consul and KRaft).

OSSeva's ZooKeeper extended support provides patched drop-in builds for 3.4, 3.5, 3.6 and 3.7, available now. Configuration and logs stay unchanged, and written attestation is available for CVEs that do not apply to your deployment. See the 3.5, 3.6 and 3.7 end-of-life pages.

Frequently asked questions

What is the most serious ZooKeeper vulnerability?

By score, CVE-2023-44981 and CVE-2024-51504 at 9.1. CVE-2023-44981 needs SASL quorum authentication enabled; CVE-2024-51504 affects only the 3.9 AdminServer.

Is ZooKeeper 3.8 end of life?

No. It is the stable line and received 3.8.7 in September 2026. No end-of-life date has been announced.

Is Kafka still using ZooKeeper?

Kafka 4.0 removed it. Kafka 3.9 is the last line that can run with ZooKeeper, and it is now archived (migration guide).

Tags

ZooKeeperCVEVulnerabilityEnd of LifeLog4j

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.