// OSSeva Blog
OperationsApache HBase Support: End-of-Life Lines, ZooKeeper and Upgrades
The short answer
Apache HBase has two active release lines, 2.5 and 2.6, and a new major version, 3.0.0, released on 5 August 2026. The HBase Reference Guide marks 2.4 and everything older as end of maintenance (EOM). HBase 2.4.18, announced on 25 May 2024, was the last patch release of the 2.4 line. If your HBase cluster runs 2.4 or 1.x, the community ships no more fixes for it.
There is a second layer most teams miss. Every HBase cluster runs on Apache ZooKeeper, and the ZooKeeper version it ships is often older than the HBase version suggests. HBase 1.7.2 bundles ZooKeeper 3.4.10, a line that reached end of life in June 2020. Keeping HBase supported means keeping both layers patched.
What Apache HBase is
Apache HBase is an open-source, distributed, column-oriented NoSQL data store that runs on the Hadoop Distributed File System (HDFS). It follows the Bigtable data model: tables of rows, grouped into column families, with sparse data and very large row counts. Teams use HBase for real-time random reads and writes on big data, such as time series, messaging and user profile stores, where a relational database would not scale. Apache Phoenix adds a SQL layer on top, and Apache Hive can query HBase tables for analytics.
Inside an HBase cluster, the HMaster assigns regions to RegionServers, RegionServers serve reads and writes, HDFS stores the files, and ZooKeeper holds the coordination state. A distributed install depends on a running ZooKeeper ensemble, which HBase can manage itself or which you run as a dedicated ZooKeeper cluster.
HBase release lines and end-of-life status
| Line | Latest release | Status | Bundled ZooKeeper |
|---|---|---|---|
| 3.0 | 3.0.0 (5 Aug 2026) | New major version | 3.8.6 |
| 2.6 | 2.6.6 (9 Jun 2026) | Active | 3.8.6 |
| 2.5 | 2.5.15 (9 Jun 2026) | Active, marked stable | 3.8.6 |
| 2.4 | 2.4.18 (May 2024), final | End of maintenance | 3.8.4 |
| 2.3 | 2.3.7, final | End of maintenance | 3.5.7 from 2.3.0 |
| 1.x | 1.7.2, final | End of maintenance | 3.4.10 |
Two details matter for security reviews. First, even the current lines bundle ZooKeeper 3.8.6, which predates the fixes for three September 2026 advisories (CVE-2026-59739, CVE-2026-59969 and CVE-2026-79993) that arrived in ZooKeeper 3.8.7. Second, HBase 2.4.18 bundles 3.8.4, which also misses CVE-2026-24281 and CVE-2026-24308. The ZooKeeper CVE reference lists every affected range.
How HBase uses ZooKeeper
- Master election and RegionServer tracking.
- Cluster coordination state and table state transitions.
- Client bootstrap in older releases, where clients found
hbase:metathrough ZooKeeper. HBase 2.5 added RpcConnectionRegistry, and 3.0 makes it the default.
HBase 3.0 reduced what clients need from ZooKeeper, but masters and RegionServers still coordinate through it. The issue to remove ZooKeeper from client connections is targeted at HBase 4. The HBase and ZooKeeper page covers each release in detail. To see what you run:
# Bundled ZooKeeper jar
ls lib/ | grep -E '^zookeeper-[0-9]'
# Is HBase managing its own ensemble?
grep HBASE_MANAGES_ZK conf/hbase-env.sh
# Ensemble address
grep -A1 hbase.zookeeper.quorum conf/hbase-site.xml
When HBASE_MANAGES_ZK is true, the bundled jar is also your ZooKeeper server, so its CVEs apply directly.
HBase inside CDH and HDP
A large share of HBase in production still runs inside a Hadoop distribution, where the HBase and ZooKeeper versions are fixed by the vendor build:
| Distribution | HBase | ZooKeeper | Vendor support ended |
|---|---|---|---|
| CDH 5.16 | 1.2.0 | 3.4.5 | December 2020 |
| CDH 6.3 | 2.1.4 | 3.4.5 | March 2022 |
| HDP 2.6.5 | 1.1.2 | 3.4.6 | December 2020 |
| HDP 3.1.0 / 3.1.5 | 2.0.2 / 2.1.6 | 3.4.6 | December 2021 |
| CDP 7.1.9 | 2.4.17 | 3.8.1 | Supported to October 2028 |
Every CDH and HDP row pairs an end-of-maintenance HBase line with a ZooKeeper 3.4 build, which has no fix for CVE-2023-44981. On these clusters an HBase upgrade usually means a platform upgrade, which is why many stay where they are. See CDH and HDP end of life for the platform view.
Upgrade paths
- 2.4 to 2.5 or 2.6. The Reference Guide lists no special steps between these 2.x lines, and says that from 2.2 they should be rolling upgradeable. Check your JDK: preliminary JDK 17 support arrived with 2.5.
- 2.0 or 2.1 to 2.2 and later. The Master procedure store must be drained of old-style procedures first (HBASE-21075), so no regions can be in transition when the old Master stops.
- 1.x to 2.x. The guide calls rolling upgrades from 1.x experimental and recommends stop, upgrade and start as the safest route. HBase 2.0 needs Java 8 and Hadoop 2.6 at minimum, and you must never run the 1.x HBCK tool against a 2.x cluster.
- 2.x to 3.0. RegionServer grouping is reimplemented, and the
hbase:namespacetable is folded intohbase:meta.
Support options for HBase
- Community support. Mailing lists and JIRA help with 2.5, 2.6 and 3.0. They do not ship fixes for EOM lines.
- Upgrade. Move to 2.5 or 2.6 on your own schedule. On CDH or HDP that is a platform migration with its own timeline.
- Extended support. Keep the current version running with patched builds while the upgrade is planned.
OSSeva's HBase extended support ships patched, signed builds for HBase 2.4 and the 1.x line today, together with patched builds of the ZooKeeper 3.4 to 3.7 ensembles underneath them. Patch covers the security backports, Assure adds a dependency map and attestation for auditors, and Operate adds 24/7 monitoring and incident response with a named engineer. The HBase 2.4 end-of-life page lists what the 2.4 line is missing. Get patched builds, or talk to an engineer about the upgrade.
Frequently asked questions
Is Apache HBase end of life?
No. The project is active: 3.0.0 shipped in August 2026, and 2.5 and 2.6 received releases in June 2026. Individual lines reach end of maintenance, and today that covers 2.4 and everything older.
Is HBase SQL or NoSQL?
HBase is a NoSQL, non-relational database with no SQL engine of its own. Apache Phoenix and Apache Hive add SQL access on top.
Does HBase 3.0 still need ZooKeeper?
Yes. Clients no longer need it by default, but masters and RegionServers still do. Removal from client connections is targeted at HBase 4.
Which ZooKeeper version does HBase 2.4 use?
HBase 2.4.18 bundles ZooKeeper 3.8.4. HBase 2.5.15, 2.6.6 and 3.0.0 bundle 3.8.6.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.