// Apache Flink extended support
Still running Flink 1.x?
Your jobs are fine. The ZooKeeper behind their HA is end of life.
Flink's community supports the current and previous minor release with bug fixes. The downloads page marks 1.20 as the long-term support release of the 1.x line, which leaves 1.19 and every earlier 1.x line outside the policy. Underneath, Flink 1.17 to 1.20 build against ZooKeeper 3.7.1, and even Flink 2.3.0 builds against 3.7.2, from a ZooKeeper line that reached end of life in February 2024. OSSeva ships patched Flink 1.x builds and patched ZooKeeper for the HA services under them.
Trusted globally by enterprises




Why Flink 1.x jobs stay where they are
A streaming job that works is the last thing anyone wants to redeploy.
Flink 2.0 changed the APIs
Moving from 1.x to 2.x means reworking jobs against changed and removed APIs, then migrating state. For teams with many long-running jobs, that is application work, planned job by job.
Support is two minor releases wide
Under the written policy, a Flink minor line leaves support as soon as two newer ones exist. The 1.20 LTS covers the last 1.x line only, so a job still on 1.19 or earlier gets no further fixes.
ZooKeeper HA ships shaded inside Flink
Flink ships ZooKeeper as flink-shaded-zookeeper, so scanners flag it under that artifact name. The 3.7.1 in Flink 1.17 to 1.20 is within the affected ranges of CVE-2023-44981 and CVE-2024-23944, and CVE-2024-23944 has no community fix on the 3.7 line.
The dates that matter
2020-12-10
Flink 1.12 adds Kubernetes HA. The announcement states the ZooKeeper dependency will not be dropped.
2024-02-02
ZooKeeper 3.7 reaches end of life.
2026-06-03
Flink 1.20.5, marked LTS, still builds against ZooKeeper 3.7.1.
2026-06-25
Flink 2.3.0, the latest stable release, builds against ZooKeeper 3.7.2.
2026-09-16
Five new ZooKeeper advisories, assessed by the project only against 3.8 and 3.9.
What OSSeva delivers
Patched Flink 1.x builds
Security fixes backported to the Flink 1.x line you run, including shaded dependencies, shipped as signed distributions and container images. Job APIs, savepoint formats and configuration stay the same.
Patched ZooKeeper for Flink HA
Patched builds of the ZooKeeper ensemble that holds JobManager leader election and checkpoint pointers, and a patched flink-shaded-zookeeper so the jar inside Flink is covered too.
HA review and 2.x planning
A review of your HA setup, a move to Kubernetes HA where Flink runs on Kubernetes, and a job-by-job plan for Flink 2.x. 24/7 operations for JobManagers, checkpoints and the ensemble are available.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Move to Flink 1.20 LTS | The last community-maintained 1.x line | It still builds against ZooKeeper 3.7.1, and the LTS ends when the community ends it. |
| Migrate to Flink 2.x | A current release line | API changes and state migration for every job, and 2.3.0 still builds against ZooKeeper 3.7.2. |
| Switch HA to Kubernetes | No ZooKeeper dependency | Only works where Flink runs on Kubernetes. YARN and bare-metal clusters need ZooKeeper. |
| OSSeva extended support | Patched Flink 1.x, patched ZooKeeper and a 2.x plan | A subscription while the jobs move. |
Support policy and release dates from flink.apache.org/downloads. HA facts from the Flink HA documentation and the Flink 1.12 announcement. Bundled ZooKeeper versions from the zookeeper.version property in Flink's root pom.xml at the release-1.19.3, release-1.20.5 and release-2.3.0 tags. CVE ranges from zookeeper.apache.org/security and NVD.
Frequently asked questions
Which Flink versions are supported?
Flink's policy is to support the current and previous minor release with bug fixes. The downloads page lists 2.3.0 as the latest stable release and marks 1.20 as the long-term support release of the 1.x line. Flink 1.19 and earlier are outside the policy.
Which ZooKeeper version does Flink use?
Flink 1.17 to 1.20, including 1.20.5, build against ZooKeeper 3.7.1. Flink 2.3.0 builds against 3.7.2. Both are on the 3.7 line, which reached end of life on 2 February 2024.
Can Flink run without ZooKeeper?
On Kubernetes, yes, using Kubernetes HA services, which Flink added in 1.12. On YARN or bare metal, high availability requires ZooKeeper.
Why does my scanner flag flink-shaded-zookeeper?
Flink ships ZooKeeper shaded under that artifact name, so scanners match it to ZooKeeper CVEs. OSSeva's patched build replaces it and comes with a VEX statement for the findings that remain.
Keep your Flink jobs running, patched.
Book a discovery call about your Flink versions, HA setup and the jobs that matter most.