https://seclists.org/oss-sec/2026/q3/786: CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Affected Software
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects ZooKeeper quorum TLS deployments using the Java SSLSocket quorum path with sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true. It applies to ZooKeeper 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5.
What does an attacker need to exploit this?
An attacker needs a CA-trusted peer certificate whose SAN does not match the host being connected to. The affected quorum TLS path accepts that certificate in FIPS mode, allowing the peer to join quorum traffic and participate in leader election and replication flows.
Are hostname-verification settings alone sufficient to prevent exploitation?
No. The issue occurs even when both ssl.quorum.hostnameVerification and ssl.quorum.clientHostnameVerification are enabled, provided the deployment is also using quorum TLS and FIPS mode.
What is the recommended remediation?
Upgrade ZooKeeper to version 3.8.7 or 3.9.6, which fix the issue.