This is an automated email from the ASF dual-hosted git repository.
anmolnar pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 252d199fb Update website: new CVEs
252d199fb is described below
commit 252d199fbc9fb411c4ad94cc3e1e2ca2df181013
Author: Andor Molnar <[email protected]>
AuthorDate: Tue Sep 15 13:05:36 2026 -0500
Update website: new CVEs
---
content/__spa-fallback.html | 4 +-
.../{manifest-069ddd01.js => manifest-59ee8d48.js} | 2 +-
.../{security-DpaQqiyu.js => security-DIxTBxOu.js} | 78 +++++++++++++++++++-
content/bylaws/index.html | 4 +-
content/credits/index.html | 4 +-
content/events/index.html | 4 +-
content/index.html | 4 +-
content/mailing-lists/index.html | 4 +-
content/news/index.html | 4 +-
content/releases/index.html | 4 +-
content/security/index.html | 82 +++++++++++++++++++++-
content/slack/index.html | 4 +-
content/version-control/index.html | 4 +-
13 files changed, 177 insertions(+), 25 deletions(-)
diff --git a/content/__spa-fallback.html b/content/__spa-fallback.html
index 5763c9694..3fec295ff 100644
--- a/content/__spa-fallback.html
+++ b/content/__spa-fallback.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" as="font"
href="/fonts/inter-latin-wght-italic.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="icon" href="/images/logo.svg"
type="image/svg+xml"/><link rel="icon" href="/favicon.ico" sizes="any"/><link
rel="modu [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" as="font"
href="/fonts/inter-latin-wght-italic.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="icon" href="/images/logo.svg"
type="image/svg+xml"/><link rel="icon" href="/favicon.ico" sizes="any"/><link
rel="modu [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -19,7 +19,7 @@
"functions. Check out
https://reactrouter.com/start/framework/route-module#hydratefallback " +
"for more information."
);
- </script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":true};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window.__reactRouterContext.streamCont
[...]
+ </script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":true};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window.__reactRouterContext.streamCont
[...]
import * as route0 from "/assets/root-Civaw3g8.js";
window.__reactRouterRouteModules = {"root":route0};
diff --git a/content/assets/manifest-069ddd01.js
b/content/assets/manifest-59ee8d48.js
similarity index 98%
rename from content/assets/manifest-069ddd01.js
rename to content/assets/manifest-59ee8d48.js
index 61ef7aa3d..dac43f685 100644
--- a/content/assets/manifest-069ddd01.js
+++ b/content/assets/manifest-59ee8d48.js
@@ -1 +1 @@
-window.__reactRouterManifest={"entry":{"module":"/assets/entry.client-fgChfYSa.js","imports":["/assets/jsx-runtime-u17CrQMm.js","/assets/chunk-6CSD65Y2-DdXLjHPL.js","/assets/index-ByRO6HJY.js"],"css":[]},"routes":{"root":{"id":"root","path":"","hasAction":false,"hasLoader":false,"hasClientAction":false,"hasClientLoader":false,"hasClientMiddleware":false,"hasDefaultExport":true,"hasErrorBoundary":true,"module":"/assets/root-Civaw3g8.js","imports":["/assets/jsx-runtime-u17CrQMm.js","/asset
[...]
\ No newline at end of file
+window.__reactRouterManifest={"entry":{"module":"/assets/entry.client-fgChfYSa.js","imports":["/assets/jsx-runtime-u17CrQMm.js","/assets/chunk-6CSD65Y2-DdXLjHPL.js","/assets/index-ByRO6HJY.js"],"css":[]},"routes":{"root":{"id":"root","path":"","hasAction":false,"hasLoader":false,"hasClientAction":false,"hasClientLoader":false,"hasClientMiddleware":false,"hasDefaultExport":true,"hasErrorBoundary":true,"module":"/assets/root-Civaw3g8.js","imports":["/assets/jsx-runtime-u17CrQMm.js","/asset
[...]
\ No newline at end of file
diff --git a/content/assets/security-DpaQqiyu.js
b/content/assets/security-DIxTBxOu.js
similarity index 70%
rename from content/assets/security-DpaQqiyu.js
rename to content/assets/security-DIxTBxOu.js
index bb41fa2ec..5e749d701 100644
--- a/content/assets/security-DpaQqiyu.js
+++ b/content/assets/security-DIxTBxOu.js
@@ -1,4 +1,4 @@
-import{w as s}from"./chunk-6CSD65Y2-DdXLjHPL.js";import{j as
e}from"./jsx-runtime-u17CrQMm.js";import{M as
t}from"./mdx-components-DzdEM0Pp.js";import"./index-BES0CLPa.js";import"./index-ByRO6HJY.js";import"./index-CUfaML0k.js";e.jsx(e.Fragment,{children:"ZooKeeper
Security"}),e.jsx(e.Fragment,{children:"Security
model"}),e.jsx(e.Fragment,{children:"Security is
opt-in"}),e.jsx(e.Fragment,{children:"In scope for security
reports"}),e.jsx(e.Fragment,{children:"Out of scope for security rep [...]
+import{w as s}from"./chunk-6CSD65Y2-DdXLjHPL.js";import{j as
e}from"./jsx-runtime-u17CrQMm.js";import{M as
t}from"./mdx-components-DzdEM0Pp.js";import"./index-BES0CLPa.js";import"./index-ByRO6HJY.js";import"./index-CUfaML0k.js";e.jsx(e.Fragment,{children:"ZooKeeper
Security"}),e.jsx(e.Fragment,{children:"Security
model"}),e.jsx(e.Fragment,{children:"Security is
opt-in"}),e.jsx(e.Fragment,{children:"In scope for security
reports"}),e.jsx(e.Fragment,{children:"Out of scope for security rep [...]
`,e.jsxs(r.p,{children:["The Apache Software Foundation takes security issues
very seriously. Due to the infrastructure nature of the Apache ZooKeeper
project specifically, we haven't had many reports over time, but it doesn't
mean that we haven't had concerns over some bugs and vulnerabilities. If you
have any concern or believe you have uncovered a vulnerability, we suggest that
you get in touch via the e-mail address
",e.jsx(r.a,{href:"mailto:[email protected]?Subject=%5BS [...]
`,e.jsxs(r.p,{children:["The ASF Security team maintains a page with a
description of how vulnerabilities are handled, check their
",e.jsx(r.a,{href:"https://security.apache.org/report/",children:"Web page"}),"
for more information."]}),`
`,e.jsx(r.h2,{id:"security-model",children:"Security model"}),`
@@ -34,6 +34,11 @@ import{w as s}from"./chunk-6CSD65Y2-DdXLjHPL.js";import{j as
e}from"./jsx-runtim
`]}),`
`,e.jsx(r.h2,{id:"vulnerability-reports",children:"Vulnerability reports"}),`
`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-84501",children:"CVE-2026-84501"})}),`
+`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-84439",children:"CVE-2026-84439"})}),`
+`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-79993",children:"CVE-2026-79993"})}),`
+`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-59969",children:"CVE-2026-59969"})}),`
+`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-59739",children:"CVE-2026-59739"})}),`
`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-24308",children:"CVE-2026-24308"})}),`
`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2026-24281",children:"CVE-2026-24281"})}),`
`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2025-58457",children:"CVE-2025-58457"})}),`
@@ -45,6 +50,77 @@ import{w as s}from"./chunk-6CSD65Y2-DdXLjHPL.js";import{j as
e}from"./jsx-runtim
`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2017-5637",children:"CVE-2017-5637"})}),`
`,e.jsx(r.li,{children:e.jsx(r.a,{href:"#cve-2016-5017",children:"CVE-2016-5017"})}),`
`]}),`
+`,e.jsx(r.p,{children:"--"}),`
+`,e.jsx(r.h3,{id:"cve-2026-84501",children:"CVE-2026-84501"}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Operational log forgery via
newline injection in EnsembleAuthenticationProvider"})}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Severity:"})," moderate"]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Affected versions:"})}),`
+`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.9.0 through 3.9.5"}),`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.8.0 through 3.8.6"}),`
+`]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Description:"})}),`
+`,e.jsx(r.p,{children:`An unauthenticated attacker can inject arbitrary fake
log lines into Apache ZooKeeper's operational log by sending a crafted
add_auth("ensemble", ...) request containing newline characters (\\n). When the
ensemble name doesn't match,
EnsembleAuthenticationProvider.handleAuthentication() logs the raw, unsanitized
name via LOG.warn(). Because SLF4J's {} placeholder preserves embedded
newlines, the attacker can forge complete log entries — with arbitrary
timestamps, l [...]
+`,e.jsx(r.p,{children:"Users are recommended to upgrade to version 3.8.7 or
3.9.6, which fixes the issue."}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Credit:"})," Youlong Chen
Institute of Computing Technology
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(finder)"]}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"References:"}),"
",e.jsx(r.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-84501",children:"https://www.cve.org/CVERecord?id=CVE-2026-84501"})]}),`
+`,e.jsx(r.hr,{}),`
+`,e.jsx(r.h3,{id:"cve-2026-84439",children:"CVE-2026-84439"}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Audit log injection via
unsanitized output from multiple sources"})}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Severity:"}),"
important"]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Affected versions:"})}),`
+`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.9.0 through 3.9.5"}),`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.8.0 through 3.8.6"}),`
+`]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Description:"})}),`
+`,e.jsx(r.p,{children:"When audit logging is enabled
(zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary
fields into Apache ZooKeeper's audit log by sending a digest authentication
request with tab characters (\\t) embedded in the username. Because the audit
log uses tab-separated key=value format, the injected tabs are parsed as
legitimate field separators, allowing the attacker to spoof audit results
(e.g., injecting result=success), forge operation types, a [...]
+`,e.jsx(r.p,{children:"A log injection vulnerability in Apache ZooKeeper
allows a client that can call setACL to inject forged key-value fields into
zookeeper_audit.log. When audit logging is enabled, the server serializes
attacker-controlled digest ACL ids into the acl= audit field without escaping
tab characters. Because audit events are emitted as tab-separated key=value
records, a crafted ACL id can make one successful setAcl event appear to
contain forged fields such as operation=de [...]
+`,e.jsx(r.p,{children:"Users are recommended to upgrade to version 3.9.6 or
3.8.7, which fixes the issue."}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Credit:"})," Youlong Chen
Institute of Computing Technology
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter)"]}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"References:"}),"
",e.jsx(r.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-84439",children:"https://www.cve.org/CVERecord?id=CVE-2026-84439"})]}),`
+`,e.jsx(r.hr,{}),`
+`,e.jsx(r.h3,{id:"cve-2026-79993",children:"CVE-2026-79993"}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Missing ACL check on
deleteContainer opcode allows unauthorized deletion of any empty
persistent/container znode"})}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Severity:"})," critical"]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Affected versions:"})}),`
+`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.9.0 through 3.9.5"}),`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.8.0 through 3.8.6"}),`
+`]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Description:"})}),`
+`,e.jsxs(r.p,{children:["The ",e.jsx(r.code,{children:"deleteContainer"}),"
opcode (0x14/20) is processed without verifying the caller's ACL permissions,
allowing any authenticated client to delete specific znodes in the data tree
regardless of the ACL restrictions on the znode or its parent. This opcode is
considered internal-only and the official client doesn't have API for it, but a
client that can open a plain TCP session on the ZooKeeper client port (2181 by
default) - with NO authe [...]
+`,e.jsx(r.p,{children:"Users are recommended to upgrade to version 3.9.6 or
3.8.7, which fixes the issue."}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Credit:"})," K
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter), z f
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter), 布豪
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(finder)"]}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"References:"}),"
",e.jsx(r.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-79993",children:"https://www.cve.org/CVERecord?id=CVE-2026-79993"})]}),`
+`,e.jsx(r.hr,{}),`
+`,e.jsx(r.h3,{id:"cve-2026-59969",children:"CVE-2026-59969"}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Improper validation of
certificate with host mismatch in FIPS mode"})}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Severity:"}),"
important"]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Affected versions:"})}),`
+`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.9.0 through 3.9.5"}),`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.8.0 through 3.8.6"}),`
+`]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Description:"})}),`
+`,e.jsx(r.p,{children:"Apache ZooKeeper quorum TLS fails to enforce peer
hostname verification in FIPS-mode deployments. When sslQuorum=true,
zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and
ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket
quorum path accepts a CA-trusted peer certificate whose SAN does not match the
connected host. A malicious or misissued peer certificate can therefore join
quorum traffic, participate in leader election, and [...]
+`,e.jsx(r.p,{children:"Users are recommended to upgrade to version 3.8.7 or
3.9.6, which fixes the issue."}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Credit:"})," Erichen
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter)"]}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"References:"}),"
",e.jsx(r.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-59969",children:"https://www.cve.org/CVERecord?id=CVE-2026-59969"})]}),`
+`,e.jsx(r.hr,{}),`
+`,e.jsx(r.h3,{id:"cve-2026-59739",children:"CVE-2026-59739"}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Information disclosure via
SetWatches reconnect replay"})}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Severity:"})," critical"]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Affected versions:"})}),`
+`,e.jsxs(r.ul,{children:[`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.9.0 through 3.9.5"}),`
+`,e.jsx(r.li,{children:"Apache ZooKeeper (org.apache.zookeeper:zookeeper)
3.8.0 through 3.8.6"}),`
+`]}),`
+`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Description:"})}),`
+`,e.jsx(r.p,{children:"Information disclosure via SetWatches reconnect replay
in Apache ZooKeeper due to missing ACL check. An attacker can discover
ACL-restricted paths by registering exists-watches on non-existent paths, then
reconnecting after the paths are created with restricted ACLs. Issue is caused
by incomplete fix for CVE-2024-23944 (ZOOKEEPER-4799). The fix added ACL
checking to WatchManager.triggerWatch(). However, DataTree.setWatches() — the
SetWatches/SetWatches2 reconnect r [...]
+`,e.jsx(r.p,{children:"Users are recommended to upgrade to version 3.9.6,
3.8.7 which fixes the issue."}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"Credit:"})," NGUYEN HONG
QUAN
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter), n0mi1k
",e.jsx(r.a,{href:"mailto:[email protected]",children:"[email protected]"}),"
(reporter)"]}),`
+`,e.jsxs(r.p,{children:[e.jsx(r.strong,{children:"References:"}),"
",e.jsx(r.a,{href:"https://www.cve.org/CVERecord?id=CVE-2026-59739",children:"https://www.cve.org/CVERecord?id=CVE-2026-59739"})]}),`
`,e.jsx(r.hr,{}),`
`,e.jsx(r.h3,{id:"cve-2026-24308",children:"CVE-2026-24308"}),`
`,e.jsx(r.p,{children:e.jsx(r.strong,{children:"Sensitive information
disclosure in client configuration handling"})}),`
diff --git a/content/bylaws/index.html b/content/bylaws/index.html
index 84c993a17..dcde5d879 100644
--- a/content/bylaws/index.html
+++ b/content/bylaws/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Bylaws - Apache
ZooKeeper</title><meta name="description" content="The bylaws under which the
Apache ZooKeeper project operates."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inter-la
[...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Bylaws - Apache
ZooKeeper</title><meta name="description" content="The bylaws under which the
Apache ZooKeeper project operates."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inter-la
[...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -75,7 +75,7 @@ <h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold
tracking-tight md:text
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/bylaws-CiRSS1O2.js";
diff --git a/content/credits/index.html b/content/credits/index.html
index 10378e454..6e7250795 100644
--- a/content/credits/index.html
+++ b/content/credits/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Credits - Apache
ZooKeeper</title><meta name="description" content="Meet the Apache ZooKeeper
PMC members and committers who develop and maintain the project."/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" a [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Credits - Apache
ZooKeeper</title><meta name="description" content="Meet the Apache ZooKeeper
PMC members and committers who develop and maintain the project."/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" a [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -27,7 +27,7 @@
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/credits-j87Taiqr.js";
diff --git a/content/events/index.html b/content/events/index.html
index 69f21acee..60a6d5eb9 100644
--- a/content/events/index.html
+++ b/content/events/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Events - Apache
ZooKeeper</title><meta name="description" content="Latest Apache ZooKeeper
release announcements and project events."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inte [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Events - Apache
ZooKeeper</title><meta name="description" content="Latest Apache ZooKeeper
release announcements and project events."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inte [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -55,7 +55,7 @@ <h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold
tracking-tight" id="10-y
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/events-CqtWeoEO.js";
diff --git a/content/index.html b/content/index.html
index c38aea7bc..d94a58992 100644
--- a/content/index.html
+++ b/content/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><link rel="preload"
as="image" href="/images/large-logo.svg"/><link rel="preload" as="image"
href="/images/dark-theme-large-logo.svg"/><title>Apache ZooKeeper</title><meta
name="description" content="Apache ZooKeeper is a high-performance coordination
service for distributed applications."/><link rel="prel [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><link rel="preload"
as="image" href="/images/large-logo.svg"/><link rel="preload" as="image"
href="/images/dark-theme-large-logo.svg"/><title>Apache ZooKeeper</title><meta
name="description" content="Apache ZooKeeper is a high-performance coordination
service for distributed applications."/><link rel="prel [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -27,7 +27,7 @@
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/home-LGrPBNW8.js";
diff --git a/content/mailing-lists/index.html b/content/mailing-lists/index.html
index 1df7a548c..c767b8236 100644
--- a/content/mailing-lists/index.html
+++ b/content/mailing-lists/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Mailing Lists - Apache
ZooKeeper</title><meta name="description" content="Subscribe to Apache
ZooKeeper mailing lists: user, developer, commits, Jira notifications, and Git
notifications."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anony [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Mailing Lists - Apache
ZooKeeper</title><meta name="description" content="Subscribe to Apache
ZooKeeper mailing lists: user, developer, commits, Jira notifications, and Git
notifications."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anony [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -82,7 +82,7 @@ <h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold
tracking-tight md:text
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/mailing-lists-nGZLziCK.js";
diff --git a/content/news/index.html b/content/news/index.html
index 79e225086..f4b2ecce2 100644
--- a/content/news/index.html
+++ b/content/news/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>News - Apache
ZooKeeper</title><meta name="description" content="Apache ZooKeeper release
notes and migration guides."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font"
href="/fonts/inter-latin-wght-it [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>News - Apache
ZooKeeper</title><meta name="description" content="Apache ZooKeeper release
notes and migration guides."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font"
href="/fonts/inter-latin-wght-it [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -396,7 +396,7 @@
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/news-K3cyLmZ7.js";
diff --git a/content/releases/index.html b/content/releases/index.html
index 1d1c59d32..46f3b6941 100644
--- a/content/releases/index.html
+++ b/content/releases/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Releases - Apache
ZooKeeper</title><meta name="description" content="Download Apache ZooKeeper
releases. Includes current, stable, and archived versions with verification
hashes and signatures."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2" crossorigin= [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Releases - Apache
ZooKeeper</title><meta name="description" content="Download Apache ZooKeeper
releases. Includes current, stable, and archived versions with verification
hashes and signatures."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2" crossorigin= [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -67,7 +67,7 @@ <h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold
tracking-tight" id="apac
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/releases-CUqE103o.js";
diff --git a/content/security/index.html b/content/security/index.html
index ac8cd3731..6262fbae3 100644
--- a/content/security/index.html
+++ b/content/security/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Security - Apache
ZooKeeper</title><meta name="description" content="How to report security
vulnerabilities and review known CVEs for Apache ZooKeeper."/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" as="font [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Security - Apache
ZooKeeper</title><meta name="description" content="How to report security
vulnerabilities and review known CVEs for Apache ZooKeeper."/><link
rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2"
type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" as="font [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -48,6 +48,11 @@ <h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold
tracking-tight" id="out-
</ul>
<h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold tracking-tight
md:text-4xl" id="vulnerability-reports">Vulnerability reports</h2>
<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-84501" data-discover="true">CVE-2026-84501</a></li>
+<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-84439" data-discover="true">CVE-2026-84439</a></li>
+<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-79993" data-discover="true">CVE-2026-79993</a></li>
+<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-59969" data-discover="true">CVE-2026-59969</a></li>
+<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-59739" data-discover="true">CVE-2026-59739</a></li>
<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-24308" data-discover="true">CVE-2026-24308</a></li>
<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2026-24281" data-discover="true">CVE-2026-24281</a></li>
<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2025-58457" data-discover="true">CVE-2025-58457</a></li>
@@ -59,6 +64,77 @@ <h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold
tracking-tight md:text
<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2017-5637" data-discover="true">CVE-2017-5637</a></li>
<li class="leading-7"><a class="text-primary font-normal no-underline
decoration-1 underline-offset-4 hover:underline hover:opacity-100"
href="/security#cve-2016-5017" data-discover="true">CVE-2016-5017</a></li>
</ul>
+<p class="mb-4 text-base leading-7 wrap-anywhere">--</p>
+<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-84501">CVE-2026-84501</h3>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Operational log
forgery via newline injection in EnsembleAuthenticationProvider</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Severity:</strong>
moderate</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Affected
versions:</strong></p>
+<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0
through 3.9.5</li>
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0
through 3.8.6</li>
+</ul>
+<p class="mb-4 text-base leading-7
wrap-anywhere"><strong>Description:</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere">An unauthenticated attacker
can inject arbitrary fake log lines into Apache ZooKeeper's operational
log by sending a crafted add_auth("ensemble", ...) request containing
newline characters (\n). When the ensemble name doesn't match,
EnsembleAuthenticationProvider.handleAuthentication() logs the raw, unsanitized
name via LOG.warn(). Because SLF4J's {} placeholder preserves embedded
newlines, the attacker can forge [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">Users are recommended to
upgrade to version 3.8.7 or 3.9.6, which fixes the issue.</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Credit:</strong>
Youlong Chen Institute of Computing Technology <a class="text-primary
font-normal no-underline decoration-1 underline-offset-4 hover:underline
hover:opacity-100"
href="mailto:[email protected]">[email protected]</a> (finder)</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>References:</strong>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-84501" target="_blank"
rel="noopener noreferrer" class="text-primary inline font-normal no-underline
decoration-0 underline-offset-4 hover:underline
hover:opacity-100">https://www.cve.org/CVERecord?id=CVE-2026-84501<!-- --> <svg
xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"
fill="none" stroke="currentColor" stroke-width="2" stro [...]
+<hr/>
+<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-84439">CVE-2026-84439</h3>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Audit log injection
via unsanitized output from multiple sources</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Severity:</strong>
important</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Affected
versions:</strong></p>
+<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0
through 3.9.5</li>
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0
through 3.8.6</li>
+</ul>
+<p class="mb-4 text-base leading-7
wrap-anywhere"><strong>Description:</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere">When audit logging is
enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject
arbitrary fields into Apache ZooKeeper's audit log by sending a digest
authentication request with tab characters (\t) embedded in the username.
Because the audit log uses tab-separated key=value format, the injected tabs
are parsed as legitimate field separators, allowing the attacker to spoof audit
results (e.g., injecting result=suc [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">A log injection
vulnerability in Apache ZooKeeper allows a client that can call setACL to
inject forged key-value fields into zookeeper_audit.log. When audit logging is
enabled, the server serializes attacker-controlled digest ACL ids into the acl=
audit field without escaping tab characters. Because audit events are emitted
as tab-separated key=value records, a crafted ACL id can make one successful
setAcl event appear to contain forged [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">Users are recommended to
upgrade to version 3.9.6 or 3.8.7, which fixes the issue.</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Credit:</strong>
Youlong Chen Institute of Computing Technology <a class="text-primary
font-normal no-underline decoration-1 underline-offset-4 hover:underline
hover:opacity-100"
href="mailto:[email protected]">[email protected]</a>
(reporter)</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>References:</strong>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-84439" target="_blank"
rel="noopener noreferrer" class="text-primary inline font-normal no-underline
decoration-0 underline-offset-4 hover:underline
hover:opacity-100">https://www.cve.org/CVERecord?id=CVE-2026-84439<!-- --> <svg
xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"
fill="none" stroke="currentColor" stroke-width="2" stro [...]
+<hr/>
+<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-79993">CVE-2026-79993</h3>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Missing ACL check on
deleteContainer opcode allows unauthorized deletion of any empty
persistent/container znode</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Severity:</strong>
critical</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Affected
versions:</strong></p>
+<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0
through 3.9.5</li>
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0
through 3.8.6</li>
+</ul>
+<p class="mb-4 text-base leading-7
wrap-anywhere"><strong>Description:</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere">The
<code>deleteContainer</code> opcode (0x14/20) is processed without verifying
the caller's ACL permissions, allowing any authenticated client to delete
specific znodes in the data tree regardless of the ACL restrictions on the
znode or its parent. This opcode is considered internal-only and the official
client doesn't have API for it, but a client that can open a plain TCP
session on the ZooKeeper client port (2181 by default [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">Users are recommended to
upgrade to version 3.9.6 or 3.8.7, which fixes the issue.</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Credit:</strong> K
<a class="text-primary font-normal no-underline decoration-1 underline-offset-4
hover:underline hover:opacity-100"
href="mailto:[email protected]">[email protected]</a> (reporter), z
f <a class="text-primary font-normal no-underline decoration-1
underline-offset-4 hover:underline hover:opacity-100"
href="mailto:[email protected]">[email protected]</a> (reporter), 布豪 <a
class="text-primary font-norm [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>References:</strong>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-79993" target="_blank"
rel="noopener noreferrer" class="text-primary inline font-normal no-underline
decoration-0 underline-offset-4 hover:underline
hover:opacity-100">https://www.cve.org/CVERecord?id=CVE-2026-79993<!-- --> <svg
xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"
fill="none" stroke="currentColor" stroke-width="2" stro [...]
+<hr/>
+<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-59969">CVE-2026-59969</h3>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Improper validation
of certificate with host mismatch in FIPS mode</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Severity:</strong>
important</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Affected
versions:</strong></p>
+<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0
through 3.9.5</li>
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0
through 3.8.6</li>
+</ul>
+<p class="mb-4 text-base leading-7
wrap-anywhere"><strong>Description:</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere">Apache ZooKeeper quorum TLS
fails to enforce peer hostname verification in FIPS-mode deployments. When
sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true,
and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket
quorum path accepts a CA-trusted peer certificate whose SAN does not match the
connected host. A malicious or misissued peer certificate can therefore join
quorum traffic, particip [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">Users are recommended to
upgrade to version 3.8.7 or 3.9.6, which fixes the issue.</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Credit:</strong>
Erichen <a class="text-primary font-normal no-underline decoration-1
underline-offset-4 hover:underline hover:opacity-100"
href="mailto:[email protected]">[email protected]</a>
(reporter)</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>References:</strong>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-59969" target="_blank"
rel="noopener noreferrer" class="text-primary inline font-normal no-underline
decoration-0 underline-offset-4 hover:underline
hover:opacity-100">https://www.cve.org/CVERecord?id=CVE-2026-59969<!-- --> <svg
xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"
fill="none" stroke="currentColor" stroke-width="2" stro [...]
+<hr/>
+<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-59739">CVE-2026-59739</h3>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Information
disclosure via SetWatches reconnect replay</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Severity:</strong>
critical</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Affected
versions:</strong></p>
+<ul class="mb-4 ml-6 list-disc space-y-2">
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0
through 3.9.5</li>
+<li class="leading-7">Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0
through 3.8.6</li>
+</ul>
+<p class="mb-4 text-base leading-7
wrap-anywhere"><strong>Description:</strong></p>
+<p class="mb-4 text-base leading-7 wrap-anywhere">Information disclosure via
SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An
attacker can discover ACL-restricted paths by registering exists-watches on
non-existent paths, then reconnecting after the paths are created with
restricted ACLs. Issue is caused by incomplete fix for CVE-2024-23944
(ZOOKEEPER-4799). The fix added ACL checking to WatchManager.triggerWatch().
However, DataTree.setWatches() — the SetWatc [...]
+<p class="mb-4 text-base leading-7 wrap-anywhere">Users are recommended to
upgrade to version 3.9.6, 3.8.7 which fixes the issue.</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Credit:</strong>
NGUYEN HONG QUAN <a class="text-primary font-normal no-underline decoration-1
underline-offset-4 hover:underline hover:opacity-100"
href="mailto:[email protected]">[email protected]</a> (reporter),
n0mi1k <a class="text-primary font-normal no-underline decoration-1
underline-offset-4 hover:underline hover:opacity-100"
href="mailto:[email protected]">[email protected]</a> (reporter)</p>
+<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>References:</strong>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-59739" target="_blank"
rel="noopener noreferrer" class="text-primary inline font-normal no-underline
decoration-0 underline-offset-4 hover:underline
hover:opacity-100">https://www.cve.org/CVERecord?id=CVE-2026-59739<!-- --> <svg
xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24"
fill="none" stroke="currentColor" stroke-width="2" stro [...]
<hr/>
<h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold tracking-tight"
id="cve-2026-24308">CVE-2026-24308</h3>
<p class="mb-4 text-base leading-7 wrap-anywhere"><strong>Sensitive
information disclosure in client configuration handling</strong></p>
@@ -208,10 +284,10 @@ <h3 class="mt-8 mb-1 scroll-mt-28 text-xl font-semibold
tracking-tight" id="cve-
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
-import * as route2 from "/assets/security-DpaQqiyu.js";
+import * as route2 from "/assets/security-DIxTBxOu.js";
window.__reactRouterRouteModules =
{"root":route0,"pages/_landing/landing-layout":route1,"routes/_landing/security":route2};
diff --git a/content/slack/index.html b/content/slack/index.html
index f87d13481..0e5930321 100644
--- a/content/slack/index.html
+++ b/content/slack/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Slack Channel - Apache
ZooKeeper</title><meta name="description" content="Connect with the Apache
ZooKeeper community on Slack."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inter-lat
[...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Slack Channel - Apache
ZooKeeper</title><meta name="description" content="Connect with the Apache
ZooKeeper community on Slack."/><link rel="preload" as="font"
href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inter-lat
[...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -34,7 +34,7 @@ <h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold
tracking-tight md:text
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/slack-QtsU4sfc.js";
diff --git a/content/version-control/index.html
b/content/version-control/index.html
index 14928f556..58084c520 100644
--- a/content/version-control/index.html
+++ b/content/version-control/index.html
@@ -1,4 +1,4 @@
-<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Version Control -
Apache ZooKeeper</title><meta name="description" content="Access the Apache
ZooKeeper source code on GitHub and Apache Gitbox."/><link rel="preload"
as="font" href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href= [...]
+<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta
name="viewport" content="width=device-width, initial-scale=1"/><link
rel="preload" as="image" href="/images/logo.svg"/><title>Version Control -
Apache ZooKeeper</title><meta name="description" content="Access the Apache
ZooKeeper source code on GitHub and Apache Gitbox."/><link rel="preload"
as="font" href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2"
crossorigin="anonymous"/><link rel="prefetch" as="font" href= [...]
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
@@ -33,7 +33,7 @@ <h2 class="mt-12 mb-4 scroll-mt-28 text-3xl font-semibold
tracking-tight md:text
console.error(error);
sessionStorage.removeItem(storageKey2);
}
- })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
+ })("react-router-scroll-positions",
null)</script><script>window.__reactRouterContext =
{"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream
= new ReadableStream({start(controller){window [...]
import * as route0 from "/assets/root-Civaw3g8.js";
import * as route1 from "/assets/landing-layout-Cdw4hfiL.js";
import * as route2 from "/assets/version-control-C9tNK4Ai.js";