Junglewise Threat Intelligence

CVE-2026-24281: Apache ZooKeeper hostname verification bypass in ZKTrustManager

CVE-2026-24281 · Severity: high · CVSS 7.4 · Published 2026-03-07

Technologies: Red Hat AMQ Broker, Red Hat Streams for Apache Kafka, Red Hat build of Debezium, Apache Zookeeper. Vendors: Red Hat, Apache.

Executive brief

Apache ZooKeeper, a service used to coordinate and manage large sets of distributed server systems, contains a security flaw in how it verifies the identity of connecting servers and clients. An attacker who can manipulate network naming records (DNS) could potentially impersonate a legitimate ZooKeeper server or client. If successful, this could allow the attacker to intercept sensitive data or disrupt the operations of the distributed system, though the attack is difficult to perform because it requires the attacker to also possess a trusted security certificate.

Technical details

A vulnerability exists in the Apache ZooKeeper ZKTrustManager where hostname verification incorrectly falls back to reverse DNS (PTR) lookups if IP SAN validation fails. An attacker who controls or can spoof PTR records may be able to impersonate a ZooKeeper server or client by presenting a valid certificate corresponding to the spoofed PTR name. While the attack requires the attacker to present a certificate trusted by the ZKTrustManager (increasing the difficulty), it allows for a bypass of intended hostname identity protections. The issue is addressed in ZooKeeper versions 3.8.6 and 3.9.5 by providing a configuration option to disable reverse DNS lookups in client and quorum protocols.

Affected products

  • Apache ZooKeeper 3.8.0 through 3.8.5, 3.9.0 through 3.9.4
  • Red Hat AMQ Broker 7.12.7, 7.13.5, 7.14.0
  • Red Hat OpenShift AI 2.25
  • Red Hat build of Debezium 2, 3
  • Red Hat Fuse 7
  • Red Hat streams for Apache Kafka 2, 3

Timeline

  • 2026-03-07: disclosed
  • 2026-03-07: advisory
  • 2026-03-07: patched

References

Related threats