Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
Apache Zookeeper may allow unauthorized access via Netty
published today
Summary
The Apache Zookeeper software uses the Netty networking library, which contains several security weaknesses. These flaws could let an attacker connect to Zookeeper and potentially read or change data without permission. Update to the latest Zookeeper and Netty versions, or apply the provided security patches, to protect your systems.
What to do
- Update apache-zookeeper to version 3.9.5-r6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| CleanStart | – | apache-zookeeper |
< 3.9.5-r6 Fix: upgrade to 3.9.5-r6
|
Original advisory text
Netty is an asynchronous, event-driven network application framework
Multiple security vulnerabilities affect the apache-zookeeper package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.
References
- https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advis... Vendor Advisory
- https://osv.dev/vulnerability/CVE-2026-62243 URL
- https://osv.dev/vulnerability/CVE-2026-75595 URL
- https://nvd.nist.gov/vuln/detail/CVE-2026-62243 URL
- https://nvd.nist.gov/vuln/detail/CVE-2026-75595 URL
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CLEANSTART-2026-JY55743 · OSV
Monitor software like this
Free during beta