Hostname Verification Flaw in Apache ZooKeeper Quorum TLS
CVE-2026-59969
Currently unrated
What is CVE-2026-59969?
A vulnerability in Apache ZooKeeper's quorum TLS configuration allows for insufficient hostname verification in FIPS-mode deployments. When specific settings related to SSL are enabled, a peer’s CA-trusted certificate can bypass hostname validation, potentially allowing a malicious or improperly issued certificate to access quorum communications. This issue can lead to unauthorized participation in quorum traffic, which opens avenues for leader election manipulation and disruption in data replication processes.
Affected Version(s)
Apache ZooKeeper 3.9.0 <= 3.9.5
Apache ZooKeeper 3.8.0 <= 3.8.6