This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch branch-3.8.8 in repository https://gitbox.apache.org/repos/asf/zookeeper.git
commit 351026b4d6dbcfd5b79636838d54439d52f53964 Author: Andor Molnar <[email protected]> AuthorDate: Wed Sep 30 20:29:39 2026 +0000 Update release notes for 3.8.8 #2 --- zookeeper-docs/src/main/resources/markdown/releasenotes.md | 11 +++++++++++ zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md | 4 ++-- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/zookeeper-docs/src/main/resources/markdown/releasenotes.md b/zookeeper-docs/src/main/resources/markdown/releasenotes.md index 2319eae15..b48418d86 100644 --- a/zookeeper-docs/src/main/resources/markdown/releasenotes.md +++ b/zookeeper-docs/src/main/resources/markdown/releasenotes.md @@ -17,8 +17,19 @@ limitations under the License. # Release Notes - ZooKeeper - Version 3.8.8 +**Important Note** + +Added two configurable multiRead limits: `zookeeper.multiRead.maxOps` (maximum read operations per multiRead request, default 1000) and `zookeeper.multiRead.maxResponseBytes` (maximum cumulative response size per multiRead request, default 64 MB). + +## Bug + * Various undisclosed CVE fixes - please check security page for details +## Improvement + +* [ZOOKEEPER-5098](https://issues.apache.org/jira/browse/ZOOKEEPER-5098) - Upgrade netty to 4.1.138 or latest to fix CVE-2026-89044 +* [ZOOKEEPER-5099](https://issues.apache.org/jira/browse/ZOOKEEPER-5099) - Upgrade jackson jars to 2.22.3 or latest to address CVE-2026-91776, CVE-2026-91777 + diff --git a/zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md b/zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md index 0f9b099ca..d5d1d0430 100644 --- a/zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md +++ b/zookeeper-docs/src/main/resources/markdown/zookeeperAdmin.md @@ -1155,7 +1155,7 @@ property, when available, is noted below. * *multiRead.maxOps* : (Java system property: **zookeeper.multiRead.maxOps**) - **New in 3.8.5:** + **New in 3.8.8:** The maximum number of read operations (getData / getChildren) permitted in a single multiRead request. A multiRead can amplify a request that is small on the wire into a very large in-memory response, because every sub-operation result is materialized and @@ -1168,7 +1168,7 @@ property, when available, is noted below. * *multiRead.maxResponseBytes* : (Java system property: **zookeeper.multiRead.maxResponseBytes**) - **New in 3.8.5:** + **New in 3.8.8:** The maximum cumulative size, in bytes, of the data materialized while serving a single multiRead request. This is the primary guard against a multiRead response-amplification denial of service. The server accumulates the size of each sub-operation result as the
