chiprook
← Security
SecurityOctober 7, 2026, 12:20

CVE-2026-59739 in ZooKeeper: existence watches leak restricted znode names

Apache ZooKeeper has an information disclosure flaw, CVE-2026-59739: existence watches on non-existent paths reveal restricted znode names when a client reconnects. Versions 3.8.0–3.8.6 and 3.9.0–3.9.5 are affected; fixes are in 3.8.7 and 3.9.6. No exploitation has been confirmed.

CVE-2026-59739 in ZooKeeper: existence watches leak restricted znode names
#Apache#ZooKeeper
Read next
Security

Apache ZooKeeper authorization bypass found in deleteContainer path

Security

TikTok says 'Screentime to Cash' program doesn't exist, removes scam ads

Security

Polymarket bug reportedly let identity thieves into existing accounts

Security

Survey: half of South Africans bypass corporate AI restrictions