Known vulnerabilities in Apache ZooKeeper

Software CPE: cpe:2.3:a:apache_foundation:zookeeper:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache ZooKeeper Apache ZooKeeper is affected by 10 known vulnerabilities: 3 high, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU150217 - Missing Authorization
CVE-2026-59739
CWE-862 Low
No
No
3.8.7, 3.9.6 16.09.2026 SB2026091652
#VU150216 - Improper Validation of Certificate with Host Mismatch
CVE-2026-59969
CWE-297 Low
No
No
3.8.7, 3.9.6 16.09.2026 SB2026091652
#VU150214 - Missing Authorization
CVE-2026-79993
CWE-862 High
No
No
3.8.7, 3.9.6 16.09.2026 SB2026091652
#VU150213 - Improper Output Neutralization for Logs
CVE-2026-84439
CWE-117 Low
No
No
3.8.7, 3.9.6 16.09.2026 SB2026091652
#VU150212 - Improper Output Neutralization for Logs
CVE-2026-84501
CWE-117 Medium
No
No
3.8.7, 3.9.6 16.09.2026 SB2026091652
#VU99975 - Authentication Bypass by Spoofing
CVE-2024-51504
CWE-290 High
No
No
3.9.3 06.11.2024 SB2024110667
SB2024121231
SB2024122015
and 12 more
#VU87570 - Improper Access Control
CVE-2024-23944
CWE-284 Low
No
No
3.8.4, 3.9.2 15.03.2024 SB2024031533
SB2024052921
SB2024061902
and 23 more
#VU83312 - Authorization Bypass Through User-Controlled Key
CVE-2023-44981
CWE-639 Medium
No
No
3.7.2, 3.8.3, 3.9.1 20.11.2023 SB2023112072
SB2023112073
SB2023112077
and 45 more
#VU12913 - Improper Authentication
CVE-2018-8012
CWE-287 Low
No
No
- 22.05.2018 SB2018052204
SB2018060404
SB2022072128
and 4 more
#VU40092 - Memory corruption
CVE-2016-5017
CWE-119 High
No
No
- 21.09.2016 SB2016092145
SB2022091313
SB2016122208
and 1 more