Zookeeper

Vendor:

First CVE: Sep 21, 2016 · Active for 9 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Zookeeper over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
Mar 7, 2026
139 days ago

CVE Severity & Scoring

Zookeeper11 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve
Oct 10, 20177.576NOYES
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client confi
Mar 7, 20267.532NONO
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impers
Mar 7, 20267.431NONO
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.net
Mar 9, 20215.930NONO
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via
Sep 21, 20168.130NONO
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the au
Oct 11, 20239.129NONO
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary
May 21, 20187.528NONO
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented i
Nov 7, 20249.127NONO
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requ
May 23, 20195.925NONO
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper:
Sep 24, 20254.319NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Zookeeper

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9.019.11.7%00
3.5.915.918.9%00
3.5.415.99.6%00
3.5.326.29.4%00
3.5.236.520.0%01
3.5.136.316.6%01
3.5.046.819.9%01
3.4.917.573.7%01
3.4.817.573.7%01
3.4.717.573.7%01
3.4.617.573.7%01
3.4.517.573.7%01
3.4.417.573.7%01
3.4.317.573.7%01
3.4.217.573.7%01
3.4.117.573.7%01
3.4.017.573.7%01