← Advisories

Apache Curator 5.9.0 Java Deserialization

High
Advisory ID
ZSL-2026-6009
Release Date
06 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
5.9.0
CVE
N/A
Tested On
Microsoft Windows 10 (x86_64), Eclipse Temurin OpenJDK 21.0.6 (LTS), Jackson 2.18.1, SLF4J 1.7.36
Summary

Apache Curator is a Java/JVM client library for Apache ZooKeeper, a distributed coordination service. It includes a high level API framework and utilities to make using Apache ZooKeeper much easier and more reliable. It also includes recipes for common use cases and extensions such as service discovery and a Java 8 asynchronous DSL.

Description

Apache Curator suffers from an unsafe deserialization vulnerability in its service-discovery component. The discovery payload is deserialized with Jackson polymorphic typing configured as Id.CLASS, which lets the serialized data name the Java class to instantiate, so an attacker who can publish a crafted discovery record (via ZooKeeper write access or rogue-service registration) can drive gadget-based deserialization on a consumer that reads it, resulting in remote code execution where a suitable gadget is present on that consumer's classpath.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
05.10.2026No response from the vendor.
06.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
06.10.2026Initial release