Hostname Verification Flaw in Apache ZooKeeper Quorum TLS
CVE-2026-59969

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-59969?

A vulnerability in Apache ZooKeeper's quorum TLS configuration allows for insufficient hostname verification in FIPS-mode deployments. When specific settings related to SSL are enabled, a peer’s CA-trusted certificate can bypass hostname validation, potentially allowing a malicious or improperly issued certificate to access quorum communications. This issue can lead to unauthorized participation in quorum traffic, which opens avenues for leader election manipulation and disruption in data replication processes.

Affected Version(s)

Apache ZooKeeper 3.9.0 <= 3.9.5

Apache ZooKeeper 3.8.0 <= 3.8.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erichen <chenyoulong20g@ict.ac.cn>
.