Back to blog

// OSSeva Blog

Operations

Apache HBase Support: End-of-Life Lines, ZooKeeper and Upgrades

Randall McClure8 min read

The short answer

Apache HBase has two active release lines, 2.5 and 2.6, and a new major version, 3.0.0, released on 5 August 2026. The HBase Reference Guide marks 2.4 and everything older as end of maintenance (EOM). HBase 2.4.18, announced on 25 May 2024, was the last patch release of the 2.4 line. If your HBase cluster runs 2.4 or 1.x, the community ships no more fixes for it.

There is a second layer most teams miss. Every HBase cluster runs on Apache ZooKeeper, and the ZooKeeper version it ships is often older than the HBase version suggests. HBase 1.7.2 bundles ZooKeeper 3.4.10, a line that reached end of life in June 2020. Keeping HBase supported means keeping both layers patched.

What Apache HBase is

Apache HBase is an open-source, distributed, column-oriented NoSQL data store that runs on the Hadoop Distributed File System (HDFS). It follows the Bigtable data model: tables of rows, grouped into column families, with sparse data and very large row counts. Teams use HBase for real-time random reads and writes on big data, such as time series, messaging and user profile stores, where a relational database would not scale. Apache Phoenix adds a SQL layer on top, and Apache Hive can query HBase tables for analytics.

Inside an HBase cluster, the HMaster assigns regions to RegionServers, RegionServers serve reads and writes, HDFS stores the files, and ZooKeeper holds the coordination state. A distributed install depends on a running ZooKeeper ensemble, which HBase can manage itself or which you run as a dedicated ZooKeeper cluster.

HBase release lines and end-of-life status

LineLatest releaseStatusBundled ZooKeeper
3.03.0.0 (5 Aug 2026)New major version3.8.6
2.62.6.6 (9 Jun 2026)Active3.8.6
2.52.5.15 (9 Jun 2026)Active, marked stable3.8.6
2.42.4.18 (May 2024), finalEnd of maintenance3.8.4
2.32.3.7, finalEnd of maintenance3.5.7 from 2.3.0
1.x1.7.2, finalEnd of maintenance3.4.10

Two details matter for security reviews. First, even the current lines bundle ZooKeeper 3.8.6, which predates the fixes for three September 2026 advisories (CVE-2026-59739, CVE-2026-59969 and CVE-2026-79993) that arrived in ZooKeeper 3.8.7. Second, HBase 2.4.18 bundles 3.8.4, which also misses CVE-2026-24281 and CVE-2026-24308. The ZooKeeper CVE reference lists every affected range.

How HBase uses ZooKeeper

  • Master election and RegionServer tracking.
  • Cluster coordination state and table state transitions.
  • Client bootstrap in older releases, where clients found hbase:meta through ZooKeeper. HBase 2.5 added RpcConnectionRegistry, and 3.0 makes it the default.

HBase 3.0 reduced what clients need from ZooKeeper, but masters and RegionServers still coordinate through it. The issue to remove ZooKeeper from client connections is targeted at HBase 4. The HBase and ZooKeeper page covers each release in detail. To see what you run:

# Bundled ZooKeeper jar
ls lib/ | grep -E '^zookeeper-[0-9]'

# Is HBase managing its own ensemble?
grep HBASE_MANAGES_ZK conf/hbase-env.sh

# Ensemble address
grep -A1 hbase.zookeeper.quorum conf/hbase-site.xml

When HBASE_MANAGES_ZK is true, the bundled jar is also your ZooKeeper server, so its CVEs apply directly.

HBase inside CDH and HDP

A large share of HBase in production still runs inside a Hadoop distribution, where the HBase and ZooKeeper versions are fixed by the vendor build:

DistributionHBaseZooKeeperVendor support ended
CDH 5.161.2.03.4.5December 2020
CDH 6.32.1.43.4.5March 2022
HDP 2.6.51.1.23.4.6December 2020
HDP 3.1.0 / 3.1.52.0.2 / 2.1.63.4.6December 2021
CDP 7.1.92.4.173.8.1Supported to October 2028

Every CDH and HDP row pairs an end-of-maintenance HBase line with a ZooKeeper 3.4 build, which has no fix for CVE-2023-44981. On these clusters an HBase upgrade usually means a platform upgrade, which is why many stay where they are. See CDH and HDP end of life for the platform view.

Upgrade paths

  • 2.4 to 2.5 or 2.6. The Reference Guide lists no special steps between these 2.x lines, and says that from 2.2 they should be rolling upgradeable. Check your JDK: preliminary JDK 17 support arrived with 2.5.
  • 2.0 or 2.1 to 2.2 and later. The Master procedure store must be drained of old-style procedures first (HBASE-21075), so no regions can be in transition when the old Master stops.
  • 1.x to 2.x. The guide calls rolling upgrades from 1.x experimental and recommends stop, upgrade and start as the safest route. HBase 2.0 needs Java 8 and Hadoop 2.6 at minimum, and you must never run the 1.x HBCK tool against a 2.x cluster.
  • 2.x to 3.0. RegionServer grouping is reimplemented, and the hbase:namespace table is folded into hbase:meta.

Support options for HBase

  1. Community support. Mailing lists and JIRA help with 2.5, 2.6 and 3.0. They do not ship fixes for EOM lines.
  2. Upgrade. Move to 2.5 or 2.6 on your own schedule. On CDH or HDP that is a platform migration with its own timeline.
  3. Extended support. Keep the current version running with patched builds while the upgrade is planned.

OSSeva's HBase extended support ships patched, signed builds for HBase 2.4 and the 1.x line today, together with patched builds of the ZooKeeper 3.4 to 3.7 ensembles underneath them. Patch covers the security backports, Assure adds a dependency map and attestation for auditors, and Operate adds 24/7 monitoring and incident response with a named engineer. The HBase 2.4 end-of-life page lists what the 2.4 line is missing. Get patched builds, or talk to an engineer about the upgrade.

Frequently asked questions

Is Apache HBase end of life?

No. The project is active: 3.0.0 shipped in August 2026, and 2.5 and 2.6 received releases in June 2026. Individual lines reach end of maintenance, and today that covers 2.4 and everything older.

Is HBase SQL or NoSQL?

HBase is a NoSQL, non-relational database with no SQL engine of its own. Apache Phoenix and Apache Hive add SQL access on top.

Does HBase 3.0 still need ZooKeeper?

Yes. Clients no longer need it by default, but masters and RegionServers still do. Removal from client connections is targeted at HBase 4.

Which ZooKeeper version does HBase 2.4 use?

HBase 2.4.18 bundles ZooKeeper 3.8.4. HBase 2.5.15, 2.6.6 and 3.0.0 bundle 3.8.6.

Tags

HBaseZooKeeperEnd of LifeHadoopCDHHDP

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.