https://seclists.org/oss-sec/2026/q3/786: CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode

Published Sep 15, 2026
·
Updated

Affected Software

2 affected components
Apache Zookeeper>=3.9.0<=3.9.5
Apache Zookeeper>=3.8.0<=3.8.6

Frequently Asked Questions

1

Which deployments are exposed to this issue?

The issue affects ZooKeeper quorum TLS deployments using the Java SSLSocket quorum path with sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true. It applies to ZooKeeper 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5.

2

What does an attacker need to exploit this?

An attacker needs a CA-trusted peer certificate whose SAN does not match the host being connected to. The affected quorum TLS path accepts that certificate in FIPS mode, allowing the peer to join quorum traffic and participate in leader election and replication flows.

3

Are hostname-verification settings alone sufficient to prevent exploitation?

No. The issue occurs even when both ssl.quorum.hostnameVerification and ssl.quorum.clientHostnameVerification are enabled, provided the deployment is also using quorum TLS and FIPS mode.

4

What is the recommended remediation?

Upgrade ZooKeeper to version 3.8.7 or 3.9.6, which fix the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203