// OSSeva Blog
SecurityHadoop End of Life: Which Apache Hadoop Versions Are Supported
The short answer
Apache Hadoop, the Apache Software Foundation project behind HDFS and YARN, has no fixed end-of-life schedule. A line is declared end of life when no volunteer steps up to do maintenance releases. By that rule, Hadoop 1.x, 2.0 to 2.9, 3.0, 3.1 and 3.2 are end of life. Hadoop 3.4 and 3.5 are the actively released lines in 2026: the latest version of Hadoop is 3.5.0 (2 April 2026), and the latest 3.4 release is 3.4.3 (24 February 2026). Hadoop 2.10 and 3.3 were never formally voted end of life, but neither has had a release since 2022 and 2023.
Apache Hadoop release lines and their status
| Line | First release | Latest release | Status |
|---|---|---|---|
| 1.x, 2.0 to 2.9, 3.0, 3.1 | n/a | n/a | End of life (Hadoop wiki) |
| 2.10 | 2.10.0 (29 Oct 2019) | 2.10.2 (31 May 2022) | No formal EOL; no releases since 2022 |
| 3.2 | n/a | 3.2.4 (22 Jul 2022) | End of life (vote passed December 2023) |
| 3.3 | 3.3.0 (14 Jul 2020) | 3.3.6 (23 Jun 2023) | No formal EOL; no releases since 2023 |
| 3.4 | 3.4.0 (17 Mar 2024) | 3.4.3 (24 Feb 2026) | Maintained |
| 3.5 | 3.5.0 (2 Apr 2026) | 3.5.0 | Maintained, current |
The 3.2 end of life came from a December 2023 vote on the Hadoop dev lists, announced on 22 December 2023. In the discussion before it, committers favoured keeping branch-2.10 alive only by cherry-picking critical CVE fixes into the branch, without new ASF releases. That is why Hadoop 2 end of life is a grey area: no vote declared 2.10 dead, but the last Hadoop 2 release you can download is still 2.10.2.
Is Hadoop still relevant in 2026?
The project is maintained. 3.5.0 is the first stable release of the 3.5 line, with 485 fixes and improvements since 3.4, and it is the first Hadoop release with full Java 17 support: Java 17 is required on the server side. What has changed is how big data is processed. Many teams replaced MapReduce with Apache Spark, and much new work goes to cloud platforms on Amazon S3 or Azure storage. The HDFS file system, YARN, Hive and HBase still run a lot of enterprise data processing on premises, often on an old line with no security updates.
The ZooKeeper inside each Hadoop line
HDFS NameNode high availability uses a ZooKeeper quorum and the ZKFailoverController, and YARN ResourceManager HA uses ZooKeeper for leader election and, by recommendation, its state store. So every production Hadoop cluster runs ZooKeeper, and each Hadoop version bundles a ZooKeeper client:
| Hadoop release | ZooKeeper | ZooKeeper line status |
|---|---|---|
| 2.10.2 | 3.4.14 | End of life 1 Jun 2020 |
| 3.3.6 | 3.6.3 | End of life 30 Dec 2022 |
| 3.4.0 | 3.8.3 | Maintained |
| 3.4.1 to 3.4.3 | 3.8.4 | Maintained |
| 3.5.0 | 3.8.6 | Maintained |
ZooKeeper 3.4.14 and 3.6.3 both ship log4j 1.2.17, and CVE-2023-44981 has no fix on either line. Hadoop's own ZooKeeper-adjacent flaw, CVE-2021-25642 (ZKConfigurationStore deserialisation in YARN, 8.8), is fixed from 2.10.2, 3.2.4 and 3.3.4. See Hadoop and ZooKeeper for the commands to find the version a cluster uses.
CDH and HDP: older Hadoop again
Most on-premises clusters run a Hadoop distribution from Cloudera, not upstream releases, and those are older still:
- CDH 6.3 ships Apache Hadoop 3.0.0 and ZooKeeper 3.4.5. CDH 6.2 and 6.3 reached end of support in March 2022.
- HDP 3.1.5 ships Apache Hadoop 3.1.1 and ZooKeeper 3.4.6. HDP 3.1 reached end of support in December 2021.
- HDP 2.6.5 ships Apache Hadoop 2.7.3 and ZooKeeper 3.4.6. HDP 2.6 ended in December 2020.
Every one of those Hadoop versions is on an upstream end-of-life line, and every ZooKeeper is 3.4. The CDH and HDP end-of-life guide has the full dates.
Your options
- Upgrade to Hadoop 3.4 or 3.5. Plan for Java 17 on 3.5 servers, and for the Hive, HBase and Spark versions that move with it.
- Move off Hadoop. A cloud data platform or lakehouse replaces HDFS and YARN, but it is a data migration.
- Keep the cluster supported while you decide.
Where OSSeva fits
OSSeva's Hadoop extended support ships patched, signed builds for end-of-life Hadoop lines today, and patches the ZooKeeper underneath: builds for ZooKeeper 3.4, 3.5, 3.6 and 3.7 are available now, with VEX attestation for scanner findings. For distributions, see CDH extended support and HDP extended support. Start with Patch, or talk to an engineer about the upgrade path.
Frequently asked questions
Does Apache Hadoop have a fixed end-of-life schedule?
No. A line is declared end of life when nobody volunteers for maintenance releases, and the community can still choose a security-only release afterwards.
What is the latest version of Hadoop?
Hadoop 3.5.0, released on 2 April 2026. The latest 3.4 release is 3.4.3.
Is Hadoop 2 end of life?
2.0 to 2.9 are formally end of life. 2.10 was never voted end of life, but its last release was 2.10.2 in May 2022, and committers favoured cherry-picking CVE fixes into the branch over new releases.
Is Hadoop 3.3 still supported?
It has not been declared end of life, but 3.3.6 (June 2023) is its latest release, and it bundles ZooKeeper 3.6.3 from an end-of-life line.
Is Hadoop obsolete?
No. It is maintained, with 3.5.0 released in 2026. Its role has narrowed as Spark and cloud platforms took over much new work.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.