Package
zookeeper-3.8
Component
jetty-http
Latest update
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This CVE is only fixed in Jetty 12.0.12+. Zookeeper ships Jetty 9.4.x, which has no backport - the upstream advisory lists no 9.x fix. Fix gated on upstream zookeeper migrating from Jetty 9.4.x to Jetty 12.x, a major version migration.
Status
Status
Fixed version
3.8.6-r1Status
Impact
GHSA-qh8g-58pp-2wxh affects jetty-http >= 7.0.0 through 12.0.11. The fix is only available in Jetty 12.0.12. Apache ZooKeeper uses Jetty 9.4.58.v20250814 for its admin server, and Jetty 9.x is EOL with no patch forthcoming. Upgrading to Jetty 12.x requires a major migration (javax to jakarta namespace) that ZooKeeper upstream has not undertaken.
Status