Author: andor Date: Wed Sep 9 17:52:20 2026 New Revision: 87385 Log: Update ZooKeeper release notes 3.9.6 release candidate 0
Modified: dev/zookeeper/zookeeper-3.9.6-candidate-0/website/releasenotes.html Modified: dev/zookeeper/zookeeper-3.9.6-candidate-0/website/releasenotes.html ============================================================================== --- dev/zookeeper/zookeeper-3.9.6-candidate-0/website/releasenotes.html Wed Sep 9 17:11:34 2026 (r87384) +++ dev/zookeeper/zookeeper-3.9.6-candidate-0/website/releasenotes.html Wed Sep 9 17:52:20 2026 (r87385) @@ -166,6 +166,7 @@ limitations under the License. <h2>Bug</h2> <ul> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-4828">ZOOKEEPER-4828</a> - Minor 3.9 broke custom TLS setup with ssl.context.supplier.class</li> +<li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-4992">ZOOKEEPER-4992</a> - Loading multiple trusted certificates with identical subject names from a PEM bundle fails</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5009">ZOOKEEPER-5009</a> - Memory Leak in zoo_sasl_client_create</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5021">ZOOKEEPER-5021</a> - zkCli.sh needs "Ctrl-D" twice to exit</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5044">ZOOKEEPER-5044</a> - NettyServerCxnxFactory.shutdown must explicitly shut down DefaultEventExecutor</li> @@ -186,6 +187,7 @@ limitations under the License. <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5041">ZOOKEEPER-5041</a> - Upgrade Netty to fix CVE-2026-33870</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5042">ZOOKEEPER-5042</a> - Enhance X-Forwarded-For setting in IPAuthenticationProvider</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5043">ZOOKEEPER-5043</a> - Disable fallback to DIGEST-MD5 in SaslServer when Fips mode is set</li> +<li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5050">ZOOKEEPER-5050</a> - Disable AdminServer and enhance documentation to highlight security considerations</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5058">ZOOKEEPER-5058</a> - Remove special characters from ensemble name before logging in EnsembleAuthenticationProvider</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5060">ZOOKEEPER-5060</a> - Update GitHub Actions versions</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5075">ZOOKEEPER-5075</a> - Upgrade jline jar to 3.30.14 or higher to fix CVE-2026-56740</li> @@ -193,7 +195,10 @@ limitations under the License. <h2>Task</h2> <ul> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5027">ZOOKEEPER-5027</a> - Upgrade deprecated GitHub Actions versions</li> +<li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5035">ZOOKEEPER-5035</a> - remove loggraph from contrib</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5048">ZOOKEEPER-5048</a> - Backport ZOOKEEPER-4912: Remove default TLS cipher overrides to branch-3.9</li> +<li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5083">ZOOKEEPER-5083</a> - Upgrade Jackson-databind to 2.22.2 to fix known security vulnerabilities</li> +<li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5085">ZOOKEEPER-5085</a> - Remove unused vulnerable prototype.js from branch-3.9 and branch-3.8</li> <li><a href="https://issues.apache.org/jira/browse/ZOOKEEPER-5086">ZOOKEEPER-5086</a> - Upgrade Netty to 4.1.137.Final</li> </ul> <p> </p>
