CVE-2026-24281

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
References
Link Resource
https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2 Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/03/07/4 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:12

Type Values Removed Values Added
CPE cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
Summary
  • (es) La verificación de nombre de host en Apache ZooKeeper ZKTrustManager recurre a DNS inverso (PTR) cuando falla la validación IP SAN, permitiendo a los atacantes que controlan o falsifican registros PTR suplantar servidores o clientes de ZooKeeper con un certificado válido para el nombre PTR. Es importante señalar que el atacante debe presentar un certificado que sea de confianza para ZKTrustManager, lo que hace que el vector de ataque sea más difícil de explotar. Se recomienda a los usuarios actualizar a la versión 3.8.6 o 3.9.5, que corrige este problema al introducir una nueva opción de configuración para deshabilitar la búsqueda de DNS inverso en los protocolos de cliente y quórum.
References () https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2 - () https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/07/4 - () http://www.openwall.com/lists/oss-security/2026/03/07/4 - Mailing List, Third Party Advisory
First Time Apache zookeeper
Apache

07 Mar 2026, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/07/4 -

07 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 09:16

Updated : 2026-03-10 18:18


NVD link : CVE-2026-24281

Mitre link : CVE-2026-24281

CVE.ORG link : CVE-2026-24281


JSON object : View

Products Affected

apache

  • zookeeper
CWE
CWE-295

Improper Certificate Validation

CWE-350

Reliance on Reverse DNS Resolution for a Security-Critical Action