CVE detail
CVE-2026-24281
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24281.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 7, 2026, 9:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2445449bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/security/cve/CVE-2026-24281access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:8509access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:34608access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:14276access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:14272access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:10184access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - http://www.openwall.com/lists/oss-security/2026/03/07/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 7, 2026, 9:16 AM - https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2lists.apache.org
No excerpt available.
Vendor Advisorylists.apache.orgMar 7, 2026, 9:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-54342CVSS 8.1 · High
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certi…
- CVE-2026-48021CVSS 9.1 · Critical
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controll…
- CVE-2026-52688CVSS 7.5 · High
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
- CVE-2026-56820CVSS 7.4 · High
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` doe…
- CVE-2026-60648CVSS 8.0 · High
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14…
- CVE-2026-56624CVSS 7.3 · High
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate…