Hostname Verification Vulnerability in Apache ZooKeeper
CVE-2026-24281
5.9MEDIUM
What is CVE-2026-24281?
A vulnerability exists in Apache ZooKeeper's ZKTrustManager where hostname verification defaults to using reverse DNS (PTR) when IP Subject Alternative Name (SAN) validation fails. This can allow attackers controlling or spoofing PTR records to impersonate ZooKeeper servers or clients that hold valid certificates for the associated PTR name. To mitigate the risk, it is advised to upgrade to versions 3.8.6 or 3.9.5, which introduce a configuration option to disable reverse DNS lookup in client and quorum protocols.
Affected Version(s)
Apache ZooKeeper 3.9.0 <= 3.9.4
Apache ZooKeeper 3.8.0 <= 3.8.5