Severity: important 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in 
FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, 
ssl.quorum.hostnameVerification=true, and 
ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket 
quorum path accepts a CA-trusted peer certificate whose SAN does not match the 
connected host. A malicious or misissued peer certificate can therefore join 
quorum traffic, participate in leader election, and enter replication flows.



Users are recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the 
issue.

Credit:

Erichen <[email protected]> (reporter)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-59969

Reply via email to