End of life

Apache HBase 2.4 end of life

Apache HBase 2.4 reached end of maintenance on 25 May 2024, when the HBase team released 2.4.18 as the last patch release for the 2.4.x line. The reference guide lists 2.4 as EOM, with 2.5 and 2.6 active. HBase 2.4.18 bundles ZooKeeper 3.8.4, which is affected by all seven ZooKeeper CVEs published in 2026.

End of life
25 May 2024
Released
Dec 2020
Final release
2.4.18
Successor
HBase 2.5 or 2.6

Date published by Apache HBase 2.4.18 release announcement and the HBase Reference Guide. We do not publish a lifecycle date we cannot source.

What actually stops on 25 May 2024

  • Patch releases on the 2.4 line. 2.4.18 was the last.
  • Security fixes for the region servers, the master and the libraries 2.4.18 bundles, including ZooKeeper 3.8.4.
  • A bundled ZooKeeper update. 2.4.18 will never pick up the fixes for CVE-2026-24281 and CVE-2026-24308 in ZooKeeper 3.8.6, or the September 2026 advisories fixed in 3.8.7.

What actually breaks in the upgrade

2.5 and 2.6 are the targets

HBase 2.5.15 is marked stable and 2.6.6 is the newest 2.x release. Both, like 3.0.0, bundle ZooKeeper 3.8.6. That is one release behind 3.8.7, so the ensemble still needs attention after the HBase upgrade.

Newer releases ship fewer Hadoop CVEs

The reference guide says that up to 2.5.10 and 2.6.1, binary releases kept an old default Hadoop 3 version and often shipped unfixed CVEs from Hadoop and its dependencies. From 2.5.11 and 2.6.2 the default tracks the latest supported Hadoop 3 release. HBase 2.4 predates that change.

ZooKeeper does not go away

HBase 3.0 made RpcConnectionRegistry the default, so clients no longer need ZooKeeper to find the cluster. The servers still require it. Master election and region server tracking run through ZooKeeper in every current release.

Cloudera's HBase is a separate line

Cloudera on premises 7.1.9 ships its own HBase 2.4 build, and 7.3.2 moves to an HBase 2.6.3 build. Those follow Cloudera's lifecycle. This page covers the upstream Apache releases.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to 2.5 or 2.6The active Apache lines, with current bundled dependencies.WeeksEngineering timeThe destination for most clusters. Check coprocessors and the Hadoop version first.
Upgrade to 3.0The new major release, from August 2026.QuartersEngineering timeWorth planning, but a larger change than 2.5 or 2.6 for a cluster moving off 2.4.
OSSeva extended support on 2.4Patched 2.4 builds and the ZooKeeper ensemble under them.Drop-inSubscriptionKeeps a 2.4 cluster patched when an application or a platform pins it.

What OSSeva does for Apache HBase 2.4

OSSeva patches this line

OSSeva patches HBase 2.4 now. Signed 2.4 builds carry backported HBase fixes, and the ZooKeeper under the cluster is patched in the same release, on the Patch, Assure and Operate tiers. You buy support for HBase; the ZooKeeper it depends on comes with it.

Apache HBase extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component that stores or processes cardholder data needs its applicable security patches. On a data platform that includes the ZooKeeper ensemble the cluster depends on, not only the query engines people see.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A platform past its end of support fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library

Apache HBase 2.4: common questions

Is HBase 2.4 end of life?

Yes. The HBase team announced 2.4.18, released on 25 May 2024, as the last patch release for the 2.4.x line, and the reference guide lists 2.4 as end of maintenance.

Which HBase version should I upgrade to?

2.5 or 2.6. The downloads page marks 2.5.15 as the stable release, and 2.6.6 is the newest 2.x release. HBase 3.0.0 shipped in August 2026.

Which ZooKeeper does HBase 2.4 bundle?

HBase 2.4.18 bundles ZooKeeper 3.8.4. That version predates the fixes in 3.8.6 and 3.8.7, including CVE-2026-24281 and the September 2026 advisories.

Does HBase 3.0 remove ZooKeeper?

No. HBase 3.0 moved the default client registry off ZooKeeper, but the servers still require it. The issue to remove ZooKeeper from client connections targets HBase 4.

Still running Apache HBase 2.4?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.