// OSSeva Blog
MigrationHive 3 End of Life: Upgrading from Hive 3 to Hive 4
The short answer
The Apache Hive community voted the 3.x release line end of life on 8 October 2024. The 2.x line reached end of life on 20 May 2024, and 1.x on 11 April 2024. No further releases or security fixes will be made for them. The last releases were 3.1.3 (8 April 2022) and 2.3.10 (9 May 2024). The current line is Hive 4, and the latest release is 4.2.1 (24 August 2026), which fixes three security vulnerabilities in the Hive Metastore, HiveServer2 and the Avro SerDe.
Hive is not discontinued. What ended is support for older lines. If you run Hive 3, the path forward is a Hive 4 migration, and it has more steps than the version number suggests.
Which Apache Hive versions are end of life
| Line | Last release | End of life |
|---|---|---|
| 1.x | 1.2.2 | 11 April 2024 |
| 2.x | 2.3.10 (9 May 2024) | 20 May 2024 |
| 3.x | 3.1.3 (8 April 2022) | 8 October 2024 |
| 4.x | 4.2.1 (24 August 2026) | Current |
The Hive Metastore (HMS) has no separate end-of-life date. It ships with each Hive release, so an HMS on 3.1 is end of life with the rest of Hive 3. From 4.1 the metastore is also available as a standalone component, in binary and Docker image formats.
What changed from Hive 3 to Hive 4
- Hive on Spark is gone. In 3.1.3,
hive.execution.engineaccepts mr, tez or spark. In 4.0.0 it accepts only mr or tez (HIVE-26134). - Tez becomes the default. From 4.1.0 the default engine is tez, and MapReduce is marked deprecated. The 4.0.1 release note already urged users to move workloads to Tez.
- Java moves up. Hive 4.0 still targets Java 8. Hive 4.1 adds JDK 17 support, and Hive 4.2 requires JDK 21 as the minimum.
- Hadoop and Tez versions move up. Hive 3.1.3 builds against Hadoop 3.1.0 and Tez 0.9.1. Hive 4.0.0 works with Hadoop 3.3.6 and Tez 0.10.3, and 4.2.x with Hadoop 3.4.1 and Tez 0.10.5.
- Iceberg. Hive 4.1 and 4.2 add much of their new work around Iceberg tables, including an Iceberg REST Catalog client in 4.2.
The practical order is platform first: Java, Hadoop and Tez, then Hive. Any job still set to hive.execution.engine=spark has to move to Tez before the upgrade.
Upgrading the metastore schema
The metastore database carries the schema version, and Hive 4 ships a chain of upgrade scripts from 3.1.0 through 3.2.0, the 4.0.0 alphas and beta, 4.0.0, 4.1.0 and 4.2.0. Back up the metastore database, then run the schema tool from the new release:
# Current schema version, then the scripts that would run, then the upgrade
schematool -dbType mysql -info
schematool -dbType mysql -upgradeSchema -dryRun
schematool -dbType mysql -upgradeSchema
Test the upgraded metastore against every client that reads it, not only HiveServer2. Spark, Trino, Impala and Presto all talk to HMS, and each has its own compatibility range.
HiveServer2 high availability and ZooKeeper
Hive still uses Apache ZooKeeper in Hive 4. The same hive.zookeeper.quorum setting drives:
- HiveServer2 dynamic service discovery, where each instance registers itself and JDBC clients connect through the ensemble;
- HiveServer2 active/passive HA, which requires service discovery;
- ZooKeeper-based locks, since
hive.lock.managerstill defaults to ZooKeeperHiveLockManager when concurrency is on without ACID transactions; - the delegation-token store and the LLAP registry.
Hive 3.1.3 bundles ZooKeeper 3.4.6, which has no fix for CVE-2023-44981 or CVE-2019-0201. Hive 4.0.0 bundles 3.8.3 and 4.2.1 bundles 3.8.4, both older than the 2026 ZooKeeper fixes. Upgrading Hive does not upgrade the ensemble your HiveServer2 instances register in. The Hive and ZooKeeper page covers each setting, and this finds the version in use:
ls $HIVE_HOME/lib | grep -E '^zookeeper-[0-9]'
grep -A1 hive.zookeeper.quorum $HIVE_HOME/conf/hive-site.xml
echo srvr | nc zk1.internal 2181 | head -1
Hive inside CDH, HDP and CDP
Many Hive 3 deployments are vendor builds. HDP 3.1 ships Hive 3.1.0, HDP 2.6.5 ships Hive 1.2.1 and 2.1.0, CDH 6.3 ships Hive 2.1.1 and CDH 5.16 ships Hive 1.1.0. All of those platforms are past vendor support. CDP 7.1.9 carries a Cloudera build of Hive 3.1 that Cloudera supports to October 2028. See CDH and HDP end of life.
Your options after Hive 3 end of life
- Upgrade to Hive 4. The long-term answer, in the order above: platform, execution engine, metastore schema, then clients.
- Migrate the workload. Some teams move SQL to another engine or a lakehouse and keep only the metastore.
- Keep Hive 3 patched while you plan. Extended support closes the gap between end of life and a tested upgrade.
OSSeva's Hive extended support ships patched, signed builds for Hive 3.1 and 2.3 today, including HiveServer2 and the metastore, together with patched builds of the ZooKeeper 3.4 to 3.7 ensembles they register in. Patch covers the security backports, Assure adds CVE attestation and a SOC 2 and HIPAA evidence package for auditors, and Operate adds 24/7 monitoring and incident response. The Hive 3 end-of-life page lists the details. Get patched builds, or talk to an engineer about the Hive 4 migration.
Frequently asked questions
When did Apache Hive 3.x reach end of life?
On 8 October 2024, after a community vote. The final 3.x release is 3.1.3.
Is Hive discontinued?
No. Hive 4 is actively developed: 4.1.0 shipped in July 2025, 4.2.0 in November 2025 and 4.2.1 in August 2026.
What is the latest version of Apache Hive?
Hive 4.2.1, released on 24 August 2026. It requires JDK 21.
Is the Hive Metastore deprecated?
No. HMS is part of Hive 4 and is now also published as a standalone component. Only the metastore versions that belong to end-of-life Hive lines are unsupported.
Can I keep running Hive 2.3 or 3.1 in production?
It will keep working, but no community fixes will arrive for new vulnerabilities in Hive or its bundled ZooKeeper client. That is a finding in most security audits unless the version is covered by extended support.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.