// OSSeva Blog
SecurityZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
The short answer
Apache ZooKeeper publishes its own advisories on the ZooKeeper security page. Thirteen CVEs have been issued since 2018, seven of them in 2026. Only two release lines still get fixes: 3.9 (current, latest 3.9.6) and 3.8 (stable, latest 3.8.7), both released on 15 September 2026. Lines 3.4 to 3.7 are end of life, so a vulnerability in Apache ZooKeeper found today is never patched there. ZooKeeper 3.10 is being prepared but is not released.
Release lines and end-of-life dates
| Line | Last release | End of life |
|---|---|---|
| 3.4 | 3.4.14 (2 Apr 2019) | 1 Jun 2020 |
| 3.5 | 3.5.10 (4 Jun 2022) | 1 Jun 2022 |
| 3.6 | 3.6.4 (30 Dec 2022) | 30 Dec 2022 |
| 3.7 | 3.7.2 (9 Oct 2023) | 2 Feb 2024 |
| 3.8 | 3.8.7 (15 Sep 2026) | None announced |
| 3.9 | 3.9.6 (15 Sep 2026) | None announced |
ZooKeeper's own CVEs, with affected and fixed versions
Scores are the CVSS 3.1 base scores shown on NVD. Where NVD has not scored a CVE, the score is the one CISA added as an ADP.
| CVE | CVSS | Affected | Fixed in | What it is |
|---|---|---|---|---|
| CVE-2018-8012 | 7.5 | before 3.4.10; 3.5.0-alpha to 3.5.3-beta | 3.4.10, 3.5.4-beta | No authentication for servers joining the quorum |
| CVE-2019-0201 | 5.9 | up to 3.4.13; 3.5.0-alpha to 3.5.4-beta | 3.4.14, 3.5.5 | getACL() leaks unsalted digest hashes |
| CVE-2023-44981 | 9.1 | all of 3.4 to 3.6; 3.7.0-3.7.1; 3.8.0-3.8.2; 3.9.0 | 3.7.2, 3.8.3, 3.9.1 | SASL quorum peer authentication bypass |
| CVE-2024-23944 | 5.3 | 3.6.0-3.7.2; 3.8.0-3.8.3; 3.9.0-3.9.1 | 3.8.4, 3.9.2 | Persistent watcher leaks child paths without an ACL check |
| CVE-2024-51504 | 9.1 | 3.9.0-3.9.2 | 3.9.3 | AdminServer IP authentication bypass via X-Forwarded-For |
| CVE-2025-58457 | 4.3 | 3.9.0-3.9.3 | 3.9.4 | AdminServer snapshot and restore with weak permission checks |
| CVE-2026-24281 | 7.4 | 3.8.0-3.8.5; 3.9.0-3.9.4 | 3.8.6, 3.9.5 | ZKTrustManager hostname verification falls back to reverse DNS (PTR) |
| CVE-2026-24308 | 7.5 | 3.8.0-3.8.5; 3.9.0-3.9.4 | 3.8.6, 3.9.5 | Improper handling of configuration values: sensitive client config logged at INFO |
| CVE-2026-59739 | 7.5 | 3.8.0-3.8.6; 3.9.0-3.9.5 | 3.8.7, 3.9.6 | SetWatches replay skips the ACL check (incomplete fix of CVE-2024-23944) |
| CVE-2026-59969 | 7.5 | 3.8.0-3.8.6; 3.9.0-3.9.5 | 3.8.7, 3.9.6 | Quorum TLS in FIPS mode skips hostname verification |
| CVE-2026-79993 | 7.5 | 3.8.0-3.8.6; 3.9.0-3.9.5 | 3.8.7, 3.9.6 | deleteContainer skips session and ACL checks |
| CVE-2026-84439 | 5.3 | 3.8.0-3.8.6; 3.9.0-3.9.5 | 3.8.7, 3.9.6 | Audit-log field injection |
| CVE-2026-84501 | 5.3 | 3.8.0-3.8.6; 3.9.0-3.9.5 | 3.8.7, 3.9.6 | Operational-log forgery via newlines |
CVE-2026-24281 lets an attacker who controls PTR records impersonate a ZooKeeper server or client. CVE-2026-24308 is an information disclosure in client log files. For both, users are recommended to upgrade to version 3.8.6 or 3.9.5. The CVE-2026-24281 fix adds a new configuration option to disable reverse DNS lookup in the client and quorum protocols; an attacker also needs a certificate the ZKTrustManager trusts, which makes it harder to exploit.
End-of-life lines with no fix
- 3.4, 3.5 and 3.6: CVE-2023-44981 has no fix. 3.6 also carries CVE-2024-23944.
- 3.7: 3.7.2 fixes CVE-2023-44981 but not CVE-2024-23944, which affects every 3.7 release.
- The 2026 CVEs: the advisories list only 3.8 and 3.9, because the project does not assess end-of-life lines. They do not say whether 3.4 to 3.7 are affected, so treat that as unknown, not as clean.
CVE-2023-44981 matters only where SASL quorum peer authentication is on (quorum.auth.enableSasl=true). The advisory says it "is not enabled by default" and that firewalling the election and quorum ports mitigates it. An attacker who reaches those ports on a vulnerable ensemble can join it and push counterfeit changes to the leader.
Bundled dependencies: log4j, Jetty and Netty
| ZooKeeper release | Logging | Jetty | Netty |
|---|---|---|---|
| 3.4.14 | log4j 1.2.17 | none | 3.10.6 |
| 3.5.5 to 3.5.9 | log4j 1.2.17 | 9.4.17 to 9.4.35 | 4.1.29 to 4.1.50 |
| 3.5.10 | reload4j 1.2.20 | 9.4.46 | 4.1.77 |
| 3.6.3 | log4j 1.2.17 | 9.4.39 | 4.1.63 |
| 3.6.4 | reload4j 1.2.24 | 9.4.49 | 4.1.86 |
| 3.7.0 | log4j 1.2.17 | 9.4.38 | 4.1.59 |
| 3.8.7, 3.9.6 | logback 1.3.15 | 9.4.58 | 4.1.137 |
- log4j 1.2.17 ships in every 3.4.x, 3.5.x up to 3.5.9, 3.6.x up to 3.6.3 and 3.7.0. Scanners report CVE-2019-17571, CVE-2021-4104, CVE-2022-23302, CVE-2022-23305 and CVE-2022-23307 against it. Each needs a specific appender or component (SocketServer, JMSAppender, JMSSink, JDBCAppender, Chainsaw). ZooKeeper's shipped
log4j.properties(checked for 3.6.3) defines only console and file appenders, so these are compliance findings unless you configured one of them. - Jetty 9 runs the AdminServer from 3.5 onward. Jetty 9 reached end of life in January 2025, yet 3.8.7 and 3.9.6 still bundle 9.4.58. Only the unreleased 3.10 moves to Jetty 12.
- Netty 4.1.29 to 4.1.63 falls inside the range for CVE-2021-37136 and CVE-2021-37137 (decoder denial of service). Whether ZooKeeper reaches those codecs is not established.
CISA KEV
No ZooKeeper CVE is in the CISA Known Exploited Vulnerabilities catalogue, and no log4j 1.x CVE either. The Log4Shell CVEs in KEV are Log4j 2, which ZooKeeper never shipped.
How to check your ZooKeeper version
Ask each ZooKeeper server directly, or read the jar on disk:
echo srvr | nc zk1.example.internal 2181 # first line: Zookeeper version
curl http://zk1.example.internal:8080/commands/srvr # AdminServer, 3.5+
ls /opt/product/lib | grep -i zookeeper # zookeeper-3.x.y.jar
From 3.5.3, srvr is the only four-letter word enabled by default. For ZooKeeper embedded in another product, the jar filename is the answer. Solr 8.11.4 ships 3.6.2, Solr 9.0.0 ships 3.7.0, CDH 5 and 6 ship 3.4.5, and CDP 7.1.6 to 7.1.8 ship 3.5.5. The ZooKeeper hub lists the version bundled by each product.
Your options
- Upgrade to 3.8.7 or 3.9.6 where you run the ensemble yourself.
- Reduce exposure: firewall the quorum and election ports, keep the client port and AdminServer off untrusted networks.
- Patch in place: a patched build of your line, when the product that embeds ZooKeeper cannot move.
- Attest: document CVEs that do not apply to your configuration.
- Migrate the product to Raft-based coordination, product by product (ZooKeeper vs etcd, Consul and KRaft).
OSSeva's ZooKeeper extended support provides patched drop-in builds for 3.4, 3.5, 3.6 and 3.7, available now. Configuration and logs stay unchanged, and written attestation is available for CVEs that do not apply to your deployment. See the 3.5, 3.6 and 3.7 end-of-life pages.
Frequently asked questions
What is the most serious ZooKeeper vulnerability?
By score, CVE-2023-44981 and CVE-2024-51504 at 9.1. CVE-2023-44981 needs SASL quorum authentication enabled; CVE-2024-51504 affects only the 3.9 AdminServer.
Is ZooKeeper 3.8 end of life?
No. It is the stable line and received 3.8.7 in September 2026. No end-of-life date has been announced.
Is Kafka still using ZooKeeper?
Kafka 4.0 removed it. Kafka 3.9 is the last line that can run with ZooKeeper, and it is now archived (migration guide).
Tags
Related articles
ZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026MigrationHashiCorp Consul End of Life: The BSL Licence, IBM Support Cycles and Your Options
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.