Security vulnerability affects the spark package. Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check.
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-JM28284.json"