30
30
30
CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
CVE-2026-59969: Apache ZooKeeper quorum TLS skips peer hostname verification in FIPS-mode deployments, enabling potential server-to-server impersonation.
Apache ZooKeeper versions 3.8.0-3.8.6 and 3.9.0-3.9.5 fail to enforce peer hostname verification for quorum TLS when FIPS mode is enabled with sslQuorum, zookeeper.fips-mode, and hostname verification settings turned on. The flaw is rated important and could allow an attacker to impersonate a quorum peer via certificate host mismatch. Users should upgrade to fixed versions.
35
45
35
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
35
30
30
45
30
30
30
35
30
30
30
30
30
30
30
30
30