Back to blog

// OSSeva Blog

Security

Hadoop End of Life: Which Apache Hadoop Versions Are Supported

Randall McClure6 min read

The short answer

Apache Hadoop, the Apache Software Foundation project behind HDFS and YARN, has no fixed end-of-life schedule. A line is declared end of life when no volunteer steps up to do maintenance releases. By that rule, Hadoop 1.x, 2.0 to 2.9, 3.0, 3.1 and 3.2 are end of life. Hadoop 3.4 and 3.5 are the actively released lines in 2026: the latest version of Hadoop is 3.5.0 (2 April 2026), and the latest 3.4 release is 3.4.3 (24 February 2026). Hadoop 2.10 and 3.3 were never formally voted end of life, but neither has had a release since 2022 and 2023.

Apache Hadoop release lines and their status

LineFirst releaseLatest releaseStatus
1.x, 2.0 to 2.9, 3.0, 3.1n/an/aEnd of life (Hadoop wiki)
2.102.10.0 (29 Oct 2019)2.10.2 (31 May 2022)No formal EOL; no releases since 2022
3.2n/a3.2.4 (22 Jul 2022)End of life (vote passed December 2023)
3.33.3.0 (14 Jul 2020)3.3.6 (23 Jun 2023)No formal EOL; no releases since 2023
3.43.4.0 (17 Mar 2024)3.4.3 (24 Feb 2026)Maintained
3.53.5.0 (2 Apr 2026)3.5.0Maintained, current

The 3.2 end of life came from a December 2023 vote on the Hadoop dev lists, announced on 22 December 2023. In the discussion before it, committers favoured keeping branch-2.10 alive only by cherry-picking critical CVE fixes into the branch, without new ASF releases. That is why Hadoop 2 end of life is a grey area: no vote declared 2.10 dead, but the last Hadoop 2 release you can download is still 2.10.2.

Is Hadoop still relevant in 2026?

The project is maintained. 3.5.0 is the first stable release of the 3.5 line, with 485 fixes and improvements since 3.4, and it is the first Hadoop release with full Java 17 support: Java 17 is required on the server side. What has changed is how big data is processed. Many teams replaced MapReduce with Apache Spark, and much new work goes to cloud platforms on Amazon S3 or Azure storage. The HDFS file system, YARN, Hive and HBase still run a lot of enterprise data processing on premises, often on an old line with no security updates.

The ZooKeeper inside each Hadoop line

HDFS NameNode high availability uses a ZooKeeper quorum and the ZKFailoverController, and YARN ResourceManager HA uses ZooKeeper for leader election and, by recommendation, its state store. So every production Hadoop cluster runs ZooKeeper, and each Hadoop version bundles a ZooKeeper client:

Hadoop releaseZooKeeperZooKeeper line status
2.10.23.4.14End of life 1 Jun 2020
3.3.63.6.3End of life 30 Dec 2022
3.4.03.8.3Maintained
3.4.1 to 3.4.33.8.4Maintained
3.5.03.8.6Maintained

ZooKeeper 3.4.14 and 3.6.3 both ship log4j 1.2.17, and CVE-2023-44981 has no fix on either line. Hadoop's own ZooKeeper-adjacent flaw, CVE-2021-25642 (ZKConfigurationStore deserialisation in YARN, 8.8), is fixed from 2.10.2, 3.2.4 and 3.3.4. See Hadoop and ZooKeeper for the commands to find the version a cluster uses.

CDH and HDP: older Hadoop again

Most on-premises clusters run a Hadoop distribution from Cloudera, not upstream releases, and those are older still:

  • CDH 6.3 ships Apache Hadoop 3.0.0 and ZooKeeper 3.4.5. CDH 6.2 and 6.3 reached end of support in March 2022.
  • HDP 3.1.5 ships Apache Hadoop 3.1.1 and ZooKeeper 3.4.6. HDP 3.1 reached end of support in December 2021.
  • HDP 2.6.5 ships Apache Hadoop 2.7.3 and ZooKeeper 3.4.6. HDP 2.6 ended in December 2020.

Every one of those Hadoop versions is on an upstream end-of-life line, and every ZooKeeper is 3.4. The CDH and HDP end-of-life guide has the full dates.

Your options

  1. Upgrade to Hadoop 3.4 or 3.5. Plan for Java 17 on 3.5 servers, and for the Hive, HBase and Spark versions that move with it.
  2. Move off Hadoop. A cloud data platform or lakehouse replaces HDFS and YARN, but it is a data migration.
  3. Keep the cluster supported while you decide.

Where OSSeva fits

OSSeva's Hadoop extended support ships patched, signed builds for end-of-life Hadoop lines today, and patches the ZooKeeper underneath: builds for ZooKeeper 3.4, 3.5, 3.6 and 3.7 are available now, with VEX attestation for scanner findings. For distributions, see CDH extended support and HDP extended support. Start with Patch, or talk to an engineer about the upgrade path.

Frequently asked questions

Does Apache Hadoop have a fixed end-of-life schedule?

No. A line is declared end of life when nobody volunteers for maintenance releases, and the community can still choose a security-only release afterwards.

What is the latest version of Hadoop?

Hadoop 3.5.0, released on 2 April 2026. The latest 3.4 release is 3.4.3.

Is Hadoop 2 end of life?

2.0 to 2.9 are formally end of life. 2.10 was never voted end of life, but its last release was 2.10.2 in May 2022, and committers favoured cherry-picking CVE fixes into the branch over new releases.

Is Hadoop 3.3 still supported?

It has not been declared end of life, but 3.3.6 (June 2023) is its latest release, and it bundles ZooKeeper 3.6.3 from an end-of-life line.

Is Hadoop obsolete?

No. It is maintained, with 3.5.0 released in 2026. Its role has narrowed as Spark and cloud platforms took over much new work.

Tags

Apache HadoopEnd of LifeZooKeeperCDHHDP

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.