// Apache Pinot support
Pinot runs on Helix. Helix runs on ZooKeeper.
Support for the whole stack, not just the query layer.
Apache Pinot uses Apache Helix for cluster management, and Helix keeps its state in ZooKeeper. Pinot's documentation calls ZooKeeper a first-class citizen of a Pinot cluster. Pinot 1.5.1, the latest release, builds against ZooKeeper 3.9.5, and Pinot 1.0.0 built against 3.6.3, a line that reached end of life in December 2022. OSSeva ships patched Pinot builds for the release you run, patches the ZooKeeper ensemble under Helix, and operates the cluster if you want it to.
Trusted globally by enterprises




Why Pinot clusters need support below the query layer
Pinot's segments, tables and routing all depend on state that lives in ZooKeeper.
Fixes arrive in the next release
Since 1.0.0, Pinot has shipped a new minor release roughly every five to seven months, and 1.5.1 is the only patch release in that series on GitHub. A fix for an older cluster usually means upgrading to the newest release.
ZooKeeper is not optional
Pinot stores cluster state, segment ideal state, table configuration and schemas in ZooKeeper through Helix. There is no ZooKeeper-free mode, so the ensemble's version and patch level are part of Pinot's security posture.
The bundled ZooKeeper trails the fixes
Pinot 1.5.1 builds against ZooKeeper 3.9.5, which is within the affected range of the five ZooKeeper advisories published on 16 September 2026 and fixed in 3.9.6. Scanners read the jar and flag the cluster.
The dates that matter
2022-12-30
ZooKeeper 3.6 reaches end of life.
2023-09-12
Pinot 1.0.0 released, built against ZooKeeper 3.6.3.
2025-09-15
Pinot 1.4.0 released, built against ZooKeeper 3.9.3.
2026-06-05
Pinot 1.5.1 released, built against ZooKeeper 3.9.5 and Helix 1.3.2.
2026-09-16
Five ZooKeeper advisories affecting 3.9.0 to 3.9.5, fixed in 3.9.6.
What OSSeva delivers
Patched Pinot builds
Security fixes backported to the Pinot 1.x release you run, including its bundled ZooKeeper client and other dependencies, shipped as signed distributions and container images.
The ZooKeeper under Helix
Patched ZooKeeper for the ensemble Pinot depends on, from 3.4 to 3.7, and support for 3.8 and 3.9, with third-party CVE attestation, including VEX, for scanner findings.
24/7 Pinot operations
Monitoring of controllers, brokers, servers, segment state and the ZooKeeper ensemble, a 15-minute P1 response and named engineers, plus upgrade execution between Pinot releases.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade to each new release | Community fixes as they ship | An upgrade and regression test for every fix you need. |
| Managed Pinot service | The provider runs the cluster | A platform migration, with data moving to the provider's environment. |
| OSSeva support | Patched Pinot and ZooKeeper, attestation and 24/7 operations | A subscription per cluster. |
| Run it yourself | Full control | Your team tracks Pinot, Helix and ZooKeeper advisories and rebuilds when needed. |
Architecture from docs.pinot.apache.org. Release dates from the apache/pinot GitHub releases. Bundled ZooKeeper and Helix versions from pom.xml at the release-1.0.0, release-1.4.0 and release-1.5.1 tags. ZooKeeper dates and CVE ranges from zookeeper.apache.org.
Frequently asked questions
Does Apache Pinot need ZooKeeper?
Yes. Pinot uses Apache Helix for cluster management, and Helix stores its state in ZooKeeper. There is no ZooKeeper-free mode.
Which ZooKeeper version does Pinot 1.5 use?
Pinot 1.5.1 builds against ZooKeeper 3.9.5, with Helix 1.3.2. The five ZooKeeper advisories published on 16 September 2026 affect 3.9.0 to 3.9.5 and are fixed in 3.9.6.
How often does Pinot release?
Since 1.0.0 in September 2023, Pinot has shipped a new minor release every five to seven months: 1.1.0, 1.2.0, 1.3.0, 1.4.0 and 1.5.0, with 1.5.1 in June 2026.
Do you support Pinot versions older than 1.5?
Yes. OSSeva ships patched builds for the Pinot 1.x release you run, and for the ZooKeeper ensemble under it.
Support for Pinot, Helix and the ZooKeeper under both.
Talk to an engineer about your Pinot clusters and their ZooKeeper ensemble.