Zookeeper
Vendor:
First CVE: Sep 21, 2016 · Active for 9 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Zookeeper over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
Mar 7, 2026
139 days ago
CVE Severity & Scoring
Zookeeper11 CVEs
36%
45%
18%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5637HIGH Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve | Oct 10, 2017 | 7.5 | 76 | NO | YES |
CVE-2026-24308HIGH Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client confi | Mar 7, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-24281HIGH Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impers | Mar 7, 2026 | 7.4 | 31 | NO | NO |
CVE-2021-21295MEDIUM Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.net | Mar 9, 2021 | 5.9 | 30 | NO | NO |
CVE-2016-5017HIGH Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via | Sep 21, 2016 | 8.1 | 30 | NO | NO |
CVE-2023-44981CRITICAL Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the au | Oct 11, 2023 | 9.1 | 29 | NO | NO |
CVE-2018-8012HIGH No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary | May 21, 2018 | 7.5 | 28 | NO | NO |
CVE-2024-51504CRITICAL When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented i | Nov 7, 2024 | 9.1 | 27 | NO | NO |
CVE-2019-0201MEDIUM An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requ | May 23, 2019 | 5.9 | 25 | NO | NO |
CVE-2025-58457MEDIUM Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions.
This issue affects Apache ZooKeeper: | Sep 24, 2025 | 4.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Zookeeper
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.9.0 | 1 | 9.1 | 1.7% | 0 | 0 |
| 3.5.9 | 1 | 5.9 | 18.9% | 0 | 0 |
| 3.5.4 | 1 | 5.9 | 9.6% | 0 | 0 |
| 3.5.3 | 2 | 6.2 | 9.4% | 0 | 0 |
| 3.5.2 | 3 | 6.5 | 20.0% | 0 | 1 |
| 3.5.1 | 3 | 6.3 | 16.6% | 0 | 1 |
| 3.5.0 | 4 | 6.8 | 19.9% | 0 | 1 |
| 3.4.9 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.8 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.7 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.6 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.5 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.4 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.3 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.2 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.1 | 1 | 7.5 | 73.7% | 0 | 1 |
| 3.4.0 | 1 | 7.5 | 73.7% | 0 | 1 |