Apache Kafka 2.8 end of life
Apache Kafka 2.8 is the last 2.x line. Its final release, 2.8.2, shipped on 19 September 2022 with the fix for CVE-2022-34917, and nothing has shipped for 2.8 since. It runs on ZooKeeper and bundles ZooKeeper 3.5.9. Later advisories, including CVE-2025-27818 and CVE-2026-35554, affect 2.8.x and have no 2.8 fix. OSSeva ships patched, signed Kafka 2.8 builds today.
- End of life
- 19 September 2022 (final release, 2.8.2)
- Released
- Apr 2021
- Final release
- 2.8.2
- Successor
- Kafka 3.9 on ZooKeeper, then 4.x in KRaft mode
Date published by Apache Kafka downloads. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 19 September 2022
- Bug-fix and security releases on the 2.8.x line. 2.8.2, released on 19 September 2022, was the last.
- Fixes for the SASL JAAS login module advisories. CVE-2023-25194 and CVE-2025-27819 (JndiLoginModule) are mitigated from 3.4.0, and CVE-2025-27818 (LdapLoginModule) from 3.9.1. All three list 2.8.x as affected.
- Fixes in the Java clients. CVE-2024-31141, arbitrary file and environment reads through ConfigProviders, is fixed in kafka-clients 3.8.0, and CVE-2026-35554, a producer buffer-pool race that can deliver messages to the wrong topic, in 3.9.2.
- Fixes for the bundled ZooKeeper 3.5.9. The ZooKeeper project maintains only 3.8 and 3.9 now, and CVE-2023-44981, a quorum SASL authorisation bypass, is fixed only in 3.7.2, 3.8.3 and 3.9.1.
What actually breaks in the upgrade
Upgrade ZooKeeper before Kafka 3.9
Kafka 3.9's upgrade notes tell ZooKeeper-based clusters to make sure ZooKeeper is on 3.8.3 or higher before the broker upgrade. A 2.8 cluster with an ensemble of the same age has two coordinated upgrades ahead of it, and the ensemble goes first.
2.8 KRaft clusters cannot be upgraded
Kafka 2.8 introduced KRaft as early access. The 3.0 upgrade notes state that upgrading to KRaft from the 2.8 early access release is not possible, so a cluster built on 2.8 KRaft has to be rebuilt. ZooKeeper-mode clusters take the supported route: upgrade to 3.9, migrate to KRaft there, then move to 4.x.
3.0 changed client defaults
From 3.0 the producer enables idempotence and sets acks to all by default, and the consumer session.timeout.ms default rose from 10 to 45 seconds. Java 8 and Scala 2.12 were deprecated in 3.0, and 4.0 brokers need Java 17. Test producer throughput and consumer group behaviour on the new defaults before the brokers move.
Old clients block 4.x
The 4.0 upgrade notes require clients, including Streams and Connect, to be on 2.1 or higher before the upgrade to 4.0. Inventory every client library in use while the cluster is still on 2.8.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to 3.9, migrate to KRaft, then 4.x | Upgrade the ZooKeeper ensemble, roll the brokers to 3.9, run the KRaft migration, then upgrade to a current 4.x release. | Months | Engineering time | The destination. Start with the ensemble, because the 3.9 upgrade notes require ZooKeeper 3.8.3 or later. |
| New 4.x cluster with MirrorMaker 2 | Build a KRaft cluster on a current release and replicate topics across before cutting clients over. | Weeks to months | Parallel infrastructure plus engineering time | Skips the in-place chain and the ZooKeeper upgrade, at the price of running two clusters during the move. |
| OSSeva patched Kafka 2.8 | Signed 2.8 builds with backported fixes for the broker, Connect and clients, plus patched ZooKeeper for the ensemble. | Days | Subscription | Keeps the cluster patched and auditable while the upgrade runs on your timeline. |
| Stay on 2.8.2 | No fixes since September 2022 for the broker, the clients or the bundled ZooKeeper. | None | Zero now | Scanners already flag it. CVE-2025-27818 and CVE-2026-35554 both list 2.8.x as affected. |
What OSSeva does for Apache Kafka 2.8
OSSeva patches this line
OSSeva ships patched, signed Kafka 2.8 builds now, with backported fixes for the broker, Kafka Connect and the Java clients, and patches the ZooKeeper ensemble under the cluster. The builds are the Apache distribution, not a fork, so they stay wire-compatible with the 2.8 clients already deployed. Patch, Assure and Operate tiers are available, and OSSeva engineers run the move to 3.9 and KRaft when the cluster is ready.
Apache Kafka extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A broker with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Apache Kafka 2.8: common questions
When did Kafka 2.8 reach end of life?
The last 2.8 release was 2.8.2, on 19 September 2022, and the project has shipped nothing for the line since. Kafka 3.0.0 had been released a year earlier, on 21 September 2021. Kafka 2.8.0 itself came out on 19 April 2021.
Is Kafka 2.8 the last 2.x version?
Yes. The next release after 2.8 was 3.0.0. Kafka 2.8 is also the first release with KRaft, as early access, and the 3.0 upgrade notes state that upgrading from that early access KRaft mode is not possible.
Which CVEs affect Kafka 2.8.2?
CVE-2023-25194, CVE-2024-31141, CVE-2025-27818, CVE-2025-27819 and CVE-2026-35554 all include 2.8.x in their affected range on NVD, and none has a 2.8 release. CVE-2022-34917, a broker memory exhaustion bug, is fixed in 2.8.2 itself.
Which ZooKeeper version does Kafka 2.8 use?
Kafka 2.8.2 bundles ZooKeeper 3.5.9. The ZooKeeper project maintains only 3.8 and 3.9, and Kafka 3.9's upgrade notes require ZooKeeper 3.8.3 or later before a ZooKeeper-mode cluster moves to 3.9.
Can I get security patches for Kafka 2.8?
Yes. OSSeva ships patched, signed Kafka 2.8 builds and patched ZooKeeper for the ensemble today, on the Patch, Assure and Operate tiers.
Still running Apache Kafka 2.8?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.