ZooKeeper 3.7.2 - Vulnerability Patch Status
==============================================

This package has been patched to address the following vulnerabilities:

FIXED VULNERABILITIES:
- GHSA-3p8m-j85q-pgmj: netty-codec upgraded to 4.1.125.Final ✓
- GHSA-389x-839f-4rhx: netty-common upgraded to 4.1.125.Final ✓
- GHSA-xq3w-v528-46rv: netty-common upgraded to 4.1.125.Final ✓
- GHSA-6mjq-h674-j845: netty-handler upgraded to 4.1.125.Final ✓
- GHSA-qp4g-569p-2xwl: jetty-http upgraded to 12.1.8 ✓
- GHSA-h46c-h94j-95f3: jackson-core upgraded to 2.18.6 ✓
- GHSA-55g7-9cwv-5qfv: snappy-java upgraded to 1.1.10.5 ✓
- GHSA-qcwq-55hx-v3vh: snappy-java upgraded to 1.1.10.5 ✓
- GHSA-fjpj-2g6w-x25r: snappy-java upgraded to 1.1.10.5 ✓
- GHSA-pqr6-cmr2-h8hf: snappy-java upgraded to 1.1.10.5 ✓

KNOWN ISSUES:
- GHSA-7286-pgfv-vxvh: ZooKeeper core vulnerability - requires upgrade to 3.7.2+ (backport not feasible)
- GHSA-r978-9m6m-6gm6: ZooKeeper core vulnerability - requires code changes

Component versions after patching:
- netty-codec: 4.1.125.Final
- netty-common: 4.1.125.Final
- netty-handler: 4.1.125.Final
- jetty-http: 12.1.8
- jackson-core: 2.18.6
- snappy-java: 1.1.10.5

Patch applied: Thu Apr 23 06:33:03 UTC 2026
Package version: 3.7.2-r7
