Apache Storm 2 end of life
Apache Storm 2 reached end of life on 22 July 2026. Storm 2.8.9 was published that day as the final 2.x release, alongside Storm 3.0.0, and the project said there will be no further bug fixes, security patches or releases in the 2.x series. Storm 3.1.0, released on 12 September 2026, is current and requires Java 25.
- End of life
- 22 July 2026
- Released
- May 2019
- Final release
- 2.8.9
- Successor
- Storm 3.x (3.1.0 is current)
Date published by Apache Storm 2.8.9 release announcement. We do not publish a lifecycle date we cannot source.
What actually stops on 22 July 2026
- Releases on the 2.x line. 2.8.9 was the last.
- Security patches. The advisory for CVE-2026-82434, which exposed the topology ZooKeeper credential to read-only users and was fixed in 3.1.0, lists only 3.0.0 as affected. It does not cover 2.x either way.
- Dependency updates. 2.8.9 included a final round of library updates, such as Netty 4.2.15, and none will follow.
What actually breaks in the upgrade
Java 25 is the real gate
Storm 3 requires Java 25. The Java API is backwards compatible with Storm 2, so most topologies move without code changes, but every Nimbus, supervisor and worker host needs the new runtime first.
Clojure topologies must be rewritten
Storm 3.0.0 removed the Clojure DSL and the storm-clojure module. Topologies written against the Clojure API have to be rewritten in Java before the upgrade. Java-only clusters are unaffected.
The lite distribution drops integrations
From 3.0.0, Storm ships a lite binary without the optional Hadoop and Kafka integration jars. Topologies that relied on those jars being on the classpath need them added back through Maven or the lib-worker directory.
ZooKeeper stays
Storm 3.1.0 still uses ZooKeeper to coordinate the cluster, and storm.zookeeper.servers is mandatory. Storm 2.8.9 and 3.1.0 both bundle ZooKeeper 3.9.5, one release behind 3.9.6.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Storm 3 | The supported line, with the same Java API. | Weeks | Engineering time | The destination, once the hosts run Java 25 and any Clojure code is gone. |
| Re-platform the topologies | Rewrite the stream processing on another engine. | Quarters | Engineering time | Only worth it when the processing logic is being redesigned anyway. |
| OSSeva extended support on Storm 2 | Patched 2.x builds and the ZooKeeper ensemble under them. | Drop-in | Subscription | Keeps Storm 2 patched while the Java 25 rollout happens. |
What OSSeva does for Apache Storm 2
OSSeva patches this line
OSSeva patches Apache Storm 2 now. Signed 2.x builds carry backported fixes for Nimbus, the supervisors and the UI, and the ZooKeeper ensemble the cluster coordinates through is patched alongside it, on the Patch, Assure and Operate tiers.
Apache Storm extended supportWhat your auditor will say
Every system component that stores or processes cardholder data needs its applicable security patches. On a data platform that includes the ZooKeeper ensemble the cluster depends on, not only the query engines people see.
Auditors ask for evidence that production systems receive security fixes. A platform past its end of support fails that test unless another supplier ships the fixes and can show which CVEs they close.
Apache Storm 2: common questions
Is Apache Storm 2 end of life?
Yes. Storm 2.8.9, released on 22 July 2026, is the final 2.x release, and the project said the 2.x branch will no longer be maintained.
Will Storm 2 topologies run on Storm 3?
Java topologies should, because the Java API is backwards compatible. Clojure topologies will not, because Storm 3 removed Clojure support. Storm 3 also requires Java 25.
Does Storm still need ZooKeeper?
Yes. The Storm 3.1.0 setup guide says Storm uses ZooKeeper to coordinate the cluster, and setting up a ZooKeeper cluster is the first step.
Which ZooKeeper does Storm 2 ship?
Storm 2.8.9 bundles ZooKeeper 3.9.5. Earlier 2.x releases shipped older lines: Storm 2.4.0 bundles 3.5.9, from a ZooKeeper line that reached end of life in June 2022.
Still running Apache Storm 2?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.