// Apache Druid support
Druid ships a new major release every few months.
Your cluster probably does not.
Apache Druid went from 25.0.0 in January 2023 to 37.0.0 in May 2026. The project publishes no support window for older releases, and every Druid advisory since 2024 was fixed in the newest line, with only one also fixed on the line before it. Druid still uses ZooKeeper by default, and Druid 25 ships ZooKeeper 3.5.9, from a line that reached end of life in June 2022. OSSeva ships patched, signed builds for the Druid release you run, patches the ZooKeeper under it, and carries out the upgrade when you are ready.
Trusted globally by enterprises




Why Druid clusters fall behind
Druid is easy to upgrade one release at a time and hard to upgrade five at once.
No stated support window
The Druid project does not say how long a release receives fixes. CVE-2026-23906, an LDAP authentication bypass, affects every release from 0.17.0 through 35.x, and the published fix is an upgrade to 36.0.0. The interim mitigation is to disable anonymous bind on the LDAP server.
ZooKeeper is still the default
Druid moved segment discovery and task management to HTTP in 25.0 and removed ZooKeeper-based segment loading in 30.0, but Coordinator and Overlord leader election still use ZooKeeper. Running without it needs the Kubernetes extension, which the docs mark as experimental.
Skipped releases add up
Major releases change defaults and remove deprecated features, as 25.0 and 30.0 did for ZooKeeper-based discovery and segment loading. A cluster several releases behind takes all of those changes at once.
The dates that matter
2022-06-01
ZooKeeper 3.5 end of life. Druid 25.0.0 still ships 3.5.9.
2023-01-04
Druid 25.0.0 makes HTTP the default for segment discovery and task management.
2024-06-17
Druid 30.0.0 removes ZooKeeper-based segment loading.
2025-03-19
Druid 31.0.2 and 32.0.1 fix CVE-2025-27888 on two release lines at once.
2026-02-09
Druid 36.0.0 released. It is the published fix for CVE-2026-23906, which affects 0.17.0 through 35.x.
2026-05-08
Druid 37.0.0 released with ZooKeeper 3.8.6.
What OSSeva delivers
Patched Druid builds
Security fixes backported to the Druid release you run, including the security extensions, delivered as signed tarballs and container images. You stay on your release until you choose to move.
The ZooKeeper under Druid
Patched builds for the ensemble behind Coordinator and Overlord leader election, including the 3.5.9 that Druid 25 ships, with configuration unchanged and VEX statements for scanner findings.
Planned Druid upgrades
A Druid upgrade across several releases, with each default change and removed feature checked against your ingestion specs, extensions and queries, then rolled out one service type at a time.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade to the latest release | Current fixes from the community | It has to be repeated every few months, and every default change across the skipped releases needs testing. |
| A commercial Druid distribution | Vendor support for the vendor's own builds | A new subscription, and a move onto that distribution. |
| OSSeva Druid support | Patched builds for the release you run, the ZooKeeper under it, and planned upgrades | A subscription for the clusters you cover. |
| Mitigate and wait | Configuration workarounds, such as disabling LDAP anonymous bind | It works advisory by advisory, and not every advisory has a workaround. |
Release dates from the Apache Druid downloads page and GitHub releases. Advisories from the ASF security advisories page for Druid. ZooKeeper usage from the Druid design documentation and upgrade notes. Bundled ZooKeeper versions from pom.xml at each release tag.
Frequently asked questions
Which Druid versions receive security fixes?
The Druid project does not publish a support window. Every advisory since 2024 was fixed in the newest release line, and only CVE-2025-27888 was also fixed on the line before it, in 31.0.2. Older releases get a fix only when the community cuts a patch release for them.
Does Apache Druid still need ZooKeeper?
Yes, by default. Druid uses ZooKeeper for current cluster state, including Coordinator and Overlord leader election. A ZooKeeper-free cluster needs the Kubernetes extension, which the Druid documentation marks as experimental.
Is Druid 25 still safe to run?
It is twelve major releases behind, it ships ZooKeeper 3.5.9 from an end-of-life line, and advisories such as CVE-2026-23906 apply to it. Exposure depends on configuration: that advisory needs the basic-security extension with LDAP and an LDAP server that allows anonymous bind.
How should we plan a Druid upgrade?
Read the upgrade notes for every release you cross, not only the target. Test ingestion specs, extensions and queries against the target in a staging cluster, then roll out one service type at a time.
Does OSSeva support the Druid database itself or only ZooKeeper?
Both. Patched Druid builds cover the Druid services and security extensions, and the ZooKeeper underneath is patched in the same support tier.
Stay on your Druid release, patched, until the upgrade is ready.
Start with Patch today. Add Assure or Operate when the cluster needs them.