CVE-2026-24281
published 2026-03-07CVE-2026-24281: Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof…
PriorityP350high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.63%
46.3th percentile
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | zookeeper | >= 0 < 3.9.5-1 | 3.9.5-1 |
| apache | zookeeper | >= 3.8.0 < 3.8.6 | 3.8.6 |
| apache | zookeeper | >= 3.9.0 < 3.9.5 | 3.9.5 |
| apache_software_foundation | apache_zookeeper | 3.8.0 – 3.8.5 | — |
| apache_software_foundation | apache_zookeeper | 3.9.0 – 3.9.4 | — |
| debian | zookeeper | < zookeeper 3.9.5-1 (forky) | zookeeper 3.9.5-1 (forky) |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
vendor_redhat·2026-03-07·CVSS 7.4
CVE-2026-24281 [HIGH] CWE-295 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
A flaw was found in Apache ZooKeeper. The ZKTrustManager component's hostname verification process can fall
Debian
CVE-2026-24281: zookeeper - Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse D...
vendor_debian·2026·CVSS 7.4
CVE-2026-24281 [HIGH] CVE-2026-24281: zookeeper - Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse D...
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.9.5-1)
sid: resolved (fixed in 3.9.5-1)
trixie: open
OSV
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
osv·2026-03-07
CVE-2026-24281 [HIGH] Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
GHSA
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
ghsa·2026-03-07
CVE-2026-24281 [HIGH] CWE-295 Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
OSV
CVE-2026-24281: Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control
osv·2026-03-07·CVSS 7.4
CVE-2026-24281 [HIGH] CVE-2026-24281: Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-24281 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
bugzilla·2026-03-07·CVSS 7.4
CVE-2026-24281 [HIGH] CVE-2026-24281 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
CVE-2026-24281 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Discussion:
This issue has been addressed in the following products:
Red Hat AMQ Broker 7.1
Wiz
CVE-2025-68161 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-68161 [MEDIUM] CVE-2025-68161 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68161 :
Apache Solr vulnerability analysis and mitigation
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true.
This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:
The attacker is able to intercept or redirect network traffic between the client and the log receiver.
The attacker can present a server certificate is
Wiz
CVE-2026-24281 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-24281 [HIGH] CVE-2026-24281 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24281 :
Java vulnerability analysis and mitigation
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Source : NVD
## 7.4
Score
Published March 7, 2026
Severity HIGH
CNA Score 5.9
Affected Technologies
Java
Apache Solr
Has Public Ex
https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2http://www.openwall.com/lists/oss-security/2026/03/07/4https://access.redhat.com/errata/RHSA-2026:10184https://access.redhat.com/errata/RHSA-2026:14272https://access.redhat.com/errata/RHSA-2026:14276https://access.redhat.com/errata/RHSA-2026:34608https://access.redhat.com/errata/RHSA-2026:8509https://access.redhat.com/security/cve/CVE-2026-24281https://bugzilla.redhat.com/show_bug.cgi?id=2445449https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24281.json
2026-03-07
Published