Bug 2542322 - CVE-2026-84501 golang-github-zookeeper-zk: Apache ZooKeeper: Operational log forgery via newline injection [fedora-all]
Summary: CVE-2026-84501 golang-github-zookeeper-zk: Apache ZooKeeper: Operational log ...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: golang-github-zookeeper-zk
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Alejandro Sáez Morollón
QA Contact:
URL:
Whiteboard: {"flaws": ["601d36c5-ad43-4df9-b053-3...
Depends On:
Blocks: CVE-2026-84501
TreeView+ depends on / blocked
 
Reported: 2026-09-28 06:27 UTC by nlevinki
Modified: 2026-09-28 06:27 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description nlevinki 2026-09-28 06:27:01 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvider.handleAuthentication() logs the raw, unsanitized name via LOG.warn(). Because SLF4J's {} placeholder preserves embedded newlines, the attacker can forge complete log entries — with arbitrary timestamps, log levels, class names, and messages — that are visually indistinguishable from genuine ZooKeeper log output.

This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from 3.8.0 through 3.8.6.

Users are recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the issue.


Note You need to log in before you can comment on or make changes to this bug.