CVE-2016-5017: Apache Zookeeper

High severity, CVSS 8.1. EPSS: 7.9% chance of exploitation in the next 30 days.

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.

Affected products

  • Apache Zookeeper: up to and including 3.4.8; version 3.5.0 only; version 3.5.1 only; version 3.5.2 only

Published 2016-09-21. Last modified 2026-06-17.