// Apache Druid support

Druid ships a new major release every few months.
Your cluster probably does not.

Apache Druid went from 25.0.0 in January 2023 to 37.0.0 in May 2026. The project publishes no support window for older releases, and every Druid advisory since 2024 was fixed in the newest line, with only one also fixed on the line before it. Druid still uses ZooKeeper by default, and Druid 25 ships ZooKeeper 3.5.9, from a line that reached end of life in June 2022. OSSeva ships patched, signed builds for the Druid release you run, patches the ZooKeeper under it, and carries out the upgrade when you are ready.

Druid 36353433323125 to 30ZooKeeper 3.5 to 3.8

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Druid clusters fall behind

Druid is easy to upgrade one release at a time and hard to upgrade five at once.

No stated support window

The Druid project does not say how long a release receives fixes. CVE-2026-23906, an LDAP authentication bypass, affects every release from 0.17.0 through 35.x, and the published fix is an upgrade to 36.0.0. The interim mitigation is to disable anonymous bind on the LDAP server.

ZooKeeper is still the default

Druid moved segment discovery and task management to HTTP in 25.0 and removed ZooKeeper-based segment loading in 30.0, but Coordinator and Overlord leader election still use ZooKeeper. Running without it needs the Kubernetes extension, which the docs mark as experimental.

Skipped releases add up

Major releases change defaults and remove deprecated features, as 25.0 and 30.0 did for ZooKeeper-based discovery and segment loading. A cluster several releases behind takes all of those changes at once.

The dates that matter

  1. 2022-06-01

    ZooKeeper 3.5 end of life. Druid 25.0.0 still ships 3.5.9.

  2. 2023-01-04

    Druid 25.0.0 makes HTTP the default for segment discovery and task management.

  3. 2024-06-17

    Druid 30.0.0 removes ZooKeeper-based segment loading.

  4. 2025-03-19

    Druid 31.0.2 and 32.0.1 fix CVE-2025-27888 on two release lines at once.

  5. 2026-02-09

    Druid 36.0.0 released. It is the published fix for CVE-2026-23906, which affects 0.17.0 through 35.x.

  6. 2026-05-08

    Druid 37.0.0 released with ZooKeeper 3.8.6.

What OSSeva delivers

1

Patched Druid builds

Security fixes backported to the Druid release you run, including the security extensions, delivered as signed tarballs and container images. You stay on your release until you choose to move.

Your Druid releaseSecurity extensionsSigned builds
2

The ZooKeeper under Druid

Patched builds for the ensemble behind Coordinator and Overlord leader election, including the 3.5.9 that Druid 25 ships, with configuration unchanged and VEX statements for scanner findings.

ZooKeeper 3.5.9Leader electionVEX
3

Planned Druid upgrades

A Druid upgrade across several releases, with each default change and removed feature checked against your ingestion specs, extensions and queries, then rolled out one service type at a time.

Druid upgradeUpgrade notesRolling upgrade

Your options, compared

OptionWhat you getTrade-off
Upgrade to the latest releaseCurrent fixes from the communityIt has to be repeated every few months, and every default change across the skipped releases needs testing.
A commercial Druid distributionVendor support for the vendor's own buildsA new subscription, and a move onto that distribution.
OSSeva Druid supportPatched builds for the release you run, the ZooKeeper under it, and planned upgradesA subscription for the clusters you cover.
Mitigate and waitConfiguration workarounds, such as disabling LDAP anonymous bindIt works advisory by advisory, and not every advisory has a workaround.

Release dates from the Apache Druid downloads page and GitHub releases. Advisories from the ASF security advisories page for Druid. ZooKeeper usage from the Druid design documentation and upgrade notes. Bundled ZooKeeper versions from pom.xml at each release tag.

Frequently asked questions

Which Druid versions receive security fixes?

The Druid project does not publish a support window. Every advisory since 2024 was fixed in the newest release line, and only CVE-2025-27888 was also fixed on the line before it, in 31.0.2. Older releases get a fix only when the community cuts a patch release for them.

Does Apache Druid still need ZooKeeper?

Yes, by default. Druid uses ZooKeeper for current cluster state, including Coordinator and Overlord leader election. A ZooKeeper-free cluster needs the Kubernetes extension, which the Druid documentation marks as experimental.

Is Druid 25 still safe to run?

It is twelve major releases behind, it ships ZooKeeper 3.5.9 from an end-of-life line, and advisories such as CVE-2026-23906 apply to it. Exposure depends on configuration: that advisory needs the basic-security extension with LDAP and an LDAP server that allows anonymous bind.

How should we plan a Druid upgrade?

Read the upgrade notes for every release you cross, not only the target. Test ingestion specs, extensions and queries against the target in a staging cluster, then roll out one service type at a time.

Does OSSeva support the Druid database itself or only ZooKeeper?

Both. Patched Druid builds cover the Druid services and security extensions, and the ZooKeeper underneath is patched in the same support tier.

Stay on your Druid release, patched, until the upgrade is ready.

Start with Patch today. Add Assure or Operate when the cluster needs them.