// Apache Storm extended support
Storm 2.8.9 was the last 2.x release.
Storm 3 needs Java 25. Your topologies may not be ready.
On 22 July 2026 the Storm project released 3.0.0 and, the same day, 2.8.9 as the final release of the 2.x line. The 2.x branch is no longer maintained. Storm 3 requires Java 25 and removes the Clojure DSL. Every Storm version still requires ZooKeeper, and 2.8.9 bundles ZooKeeper 3.9.5, which predates the fixes released in September 2026. OSSeva ships patched, signed Storm 2.x builds today, patches the ZooKeeper under them, and moves topologies to Storm 3 once the Java work is done.
Trusted globally by enterprises




Why Storm 2.x clusters are stuck
The Storm API barely changed. The platform under it did.
Java 25 is a platform change
Storm 3.0 requires Java 25. Hosts, container images, JVM flags and every library on the topology classpath have to move with it, which is usually a bigger job than the Storm upgrade itself.
Clojure topologies need porting
Storm 3.0 removed the Clojure DSL. The Java API stays backwards-compatible with 2.x, but topologies written in Clojure have to be ported before they can run on 3.x.
ZooKeeper is still required
Nimbus and the supervisors coordinate through ZooKeeper, and storm.zookeeper.servers is mandatory configuration in 3.1.0 as well. Storm 2.8.9 and 3.1.0 both bundle ZooKeeper 3.9.5, and the five advisories of 16 September 2026 were fixed in 3.9.6. Storm 2.4.0 bundles 3.5.9, from a line that reached end of life in June 2022.
The dates that matter
2022-06-01
ZooKeeper 3.5 end of life. Storm 2.4.0 bundles 3.5.9.
2026-07-22
Storm 3.0.0 released with a Java 25 requirement. Storm 2.8.9 released the same day as the final 2.x release.
2026-09-12
Storm 3.1.0 released. A ZooKeeper cluster is still step one of cluster setup.
2026-09-16
Five ZooKeeper advisories fixed in 3.9.6 and 3.8.7. Storm 2.8.9 and 3.1.0 bundle 3.9.5.
What OSSeva delivers
Patched Storm 2.x builds
Backported security fixes for Nimbus, the supervisors, the UI and the client on the 2.x release you run, delivered as signed tarballs, Maven artifacts and container images on the Java version you run today.
The ZooKeeper under Storm
Patched builds of ZooKeeper 3.4 to 3.7 and support for 3.8 and 3.9, for the ensemble that holds heartbeats and assignments. VEX statements cover the bundled jar your scanner flags.
Storm 3 migration
Java 25 readiness for hosts and dependencies, Clojure topology ports, and a topology-by-topology cut-over to Storm 3.1.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade to Storm 3 now | A maintained Storm line | Java 25 across every host and dependency, and Clojure topologies ported first. |
| Replace Storm | A different stream processing engine | Every topology rewritten and retested. |
| OSSeva extended support | Patched Storm 2.x and ZooKeeper today, and the move to Storm 3 | A subscription while 2.x stays in production. |
| Stay on 2.8.9 unpatched | Nothing more from the community | New Storm and ZooKeeper advisories stay open on a branch nobody maintains. |
Release dates and the Java 25 requirement from the storm.apache.org release announcements. The ZooKeeper requirement from the Storm 3.1.0 cluster setup guide. Bundled ZooKeeper versions from pom.xml at each release tag. ZooKeeper advisories from zookeeper.apache.org/security.
Frequently asked questions
Is Storm 2.x end of life?
Yes. Storm 2.8.9, released on 22 July 2026 alongside 3.0.0, is the final 2.x release, and the project no longer maintains the 2.x branch.
What Java version does Storm 3 need?
Java 25. The Storm 3.0.0 release announcement says to upgrade the environment before migrating. The Java API is backwards-compatible with 2.x, and the Clojure DSL is removed.
Does Storm 3 still use ZooKeeper?
Yes. The 3.1.0 setup guide makes a ZooKeeper cluster step one, and storm.zookeeper.servers is mandatory configuration.
Can we keep running Storm 2.x?
With patched builds, yes, for as long as the Java 25 work takes. OSSeva ships patched Storm 2.x and ZooKeeper builds now, so the migration can follow the platform upgrade rather than race it.
Which support tier fits a Storm cluster?
Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.
Keep Storm 2.x patched until Java 25 is ready.
Start with Patch today. Add Assure or Operate when the cluster needs them.