Apache Kafka 3.9 end of life
Apache Kafka 3.9 is the last Kafka line that can run on ZooKeeper, and the project has archived it. Its final release, 3.9.2, shipped on 21 February 2026. The supported lines are now 4.1, 4.2 and 4.3, which run only in KRaft mode. Kafka 3.9 bundles ZooKeeper 3.8.4. OSSeva ships patched Kafka 3.9 builds and patches the ZooKeeper ensemble under them.
- End of life
- 21 February 2026 (final release; line archived)
- Released
- Nov 2024
- Final release
- 3.9.2
- Successor
- Kafka 4.1, 4.2 or 4.3 in KRaft mode
Date published by Apache Kafka downloads. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 21 February 2026
- Bug-fix and security releases on the 3.9.x line. 3.9.2 was the last, and 3.9 is listed under archived releases.
- Fixes for the bundled ZooKeeper 3.8.4. CVE-2026-24281 and CVE-2026-24308 are fixed in ZooKeeper 3.8.6 and the September 2026 advisories in 3.8.7, and no Kafka 3.9 release ships either.
- Community support for ZooKeeper mode itself. Every supported Kafka release requires KRaft.
What actually breaks in the upgrade
Migrate on 3.9, then upgrade
Kafka 4.0 has no ZooKeeper mode and no ZooKeeper migration. The move to KRaft has to happen on 3.x, with 3.9 as the bridge release, before any 4.x upgrade.
Old clients block 4.x
KIP-896 removed old protocol API versions in 4.0. Brokers must be on 2.1 or later before Java clients move to 4.0, and clients older than 2.1 cannot talk to 4.x brokers. Inventory the clients before planning the broker upgrade.
Java 17 and Log4j2 arrive with 4.0
Kafka 4.0 brokers, Connect and tools need Java 17, while clients and Kafka Streams need Java 11. Logging moved from Log4j to Log4j2, so custom logging configuration has to be rewritten.
Reach 3.9.2 first
CVE-2026-35554, a producer buffer-pool race that can deliver messages to the wrong topic, is fixed in 3.9.2. Clusters on 3.9.0 or 3.9.1 should move to 3.9.2 before anything else.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Migrate to KRaft, then upgrade to 4.x | Run the ZooKeeper to KRaft migration on 3.9, then upgrade to 4.1 or later. | Weeks to months | Engineering time | The destination, with a client inventory first. |
| Amazon MSK on 3.9 | MSK commits to extended support for 3.9 for at least two years from its 21 April 2025 release there. | Migration to MSK | MSK pricing | Relevant only for clusters already on or moving to AWS. |
| OSSeva patched Kafka 3.9 | Signed 3.9 builds plus patched ZooKeeper for the ensemble. | Days | Subscription | Keeps ZooKeeper-mode clusters patched while the KRaft migration runs on your timeline. |
| Stay on archived 3.9.2 | No further fixes for the broker or its bundled ZooKeeper. | None | Zero now | Scanners already flag the bundled ZooKeeper 3.8.4. |
What OSSeva does for Apache Kafka 3.9
OSSeva patches this line
OSSeva ships patched, signed Kafka 3.9 builds now and patches the ZooKeeper ensemble under ZooKeeper-mode clusters, with VEX attestation that shows auditors which ZooKeeper CVEs apply. Patch, Assure and Operate tiers are available, and OSSeva engineers run the ZooKeeper to KRaft migration when the cluster is ready.
Apache Kafka extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A runtime or broker with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Apache Kafka 3.9: common questions
Is Kafka 3.9 still supported?
Not by the Apache Kafka project. 3.9.2, released on 21 February 2026, was the final release, and 3.9 is listed under archived releases. The supported lines are 4.1, 4.2 and 4.3.
Is Kafka 3.9 the last version with ZooKeeper?
Yes. Kafka 4.0, released on 18 March 2025, removed ZooKeeper mode, so 3.9 is the last line that can run on ZooKeeper and the bridge for the KRaft migration.
Which ZooKeeper version does Kafka 3.9 bundle?
ZooKeeper 3.8.4. Fixes for CVE-2026-24281, CVE-2026-24308 and the September 2026 ZooKeeper advisories arrived in 3.8.6 and 3.8.7.
Can I keep Kafka 3.9 on ZooKeeper and stay patched?
Yes. OSSeva ships patched Kafka 3.9 builds and patched ZooKeeper for the ensemble today.
Still running Apache Kafka 3.9?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.