CVE-2026-59969

Source
https://cve.org/CVERecord?id=CVE-2026-59969
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59969.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59969
Aliases
Downstream
Published
2026-09-16T09:27:00Z
Modified
2026-09-20T11:46:48Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Details

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose SAN does not match the connected host. A malicious or misissued peer certificate can therefore join quorum traffic, participate in leader election, and enter replication flows.

Users are recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-297"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59969.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.9.0"
                },
                {
                    "last_affected": "3.9.5"
                },
                {
                    "introduced": "3.8.0"
                },
                {
                    "last_affected": "3.8.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/apache/zookeeper

Affected ranges

Type
GIT
Repo
https://github.com/apache/zookeeper
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.8.0"
        },
        {
            "fixed": "3.8.7"
        },
        {
            "introduced": "3.9.0"
        },
        {
            "fixed": "3.9.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

release-3.*
release-3.9.0
release-3.9.0-1
release-3.9.1
release-3.9.1-0
release-3.9.2
release-3.9.2-0
release-3.9.3
release-3.9.3-0
release-3.9.3-1
release-3.9.3-2
release-3.9.4
release-3.9.4-0
release-3.9.4-1
release-3.9.4-2
release-3.9.5
release-3.9.5-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59969.json"