Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

Apache Zookeeper may allow unauthorized access via Netty

published today
Summary

The Apache Zookeeper software uses the Netty networking library, which contains several security weaknesses. These flaws could let an attacker connect to Zookeeper and potentially read or change data without permission. Update to the latest Zookeeper and Netty versions, or apply the provided security patches, to protect your systems.

What to do
  • Update apache-zookeeper to version 3.9.5-r6.
Affected software
Ecosystem VendorProductAffected versions
CleanStart – apache-zookeeper < 3.9.5-r6
Fix: upgrade to 3.9.5-r6
Original advisory text
Netty is an asynchronous, event-driven network application framework
Multiple security vulnerabilities affect the apache-zookeeper package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.
Severity
9.8 Critical
CVSS 3.1: 9.8 (OSV)
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
Monitor software like this
Free during beta