// Apache Flink extended support

Still running Flink 1.x?
Your jobs are fine. The ZooKeeper behind their HA is end of life.

Flink's community supports the current and previous minor release with bug fixes. The downloads page marks 1.20 as the long-term support release of the 1.x line, which leaves 1.19 and every earlier 1.x line outside the policy. Underneath, Flink 1.17 to 1.20 build against ZooKeeper 3.7.1, and even Flink 2.3.0 builds against 3.7.2, from a ZooKeeper line that reached end of life in February 2024. OSSeva ships patched Flink 1.x builds and patched ZooKeeper for the HA services under them.

Flink 1.191.181.17 and earlierFlink 1.20 LTSZooKeeper HA (3.7.1)flink-shaded-zookeeper

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Flink 1.x jobs stay where they are

A streaming job that works is the last thing anyone wants to redeploy.

Flink 2.0 changed the APIs

Moving from 1.x to 2.x means reworking jobs against changed and removed APIs, then migrating state. For teams with many long-running jobs, that is application work, planned job by job.

Support is two minor releases wide

Under the written policy, a Flink minor line leaves support as soon as two newer ones exist. The 1.20 LTS covers the last 1.x line only, so a job still on 1.19 or earlier gets no further fixes.

ZooKeeper HA ships shaded inside Flink

Flink ships ZooKeeper as flink-shaded-zookeeper, so scanners flag it under that artifact name. The 3.7.1 in Flink 1.17 to 1.20 is within the affected ranges of CVE-2023-44981 and CVE-2024-23944, and CVE-2024-23944 has no community fix on the 3.7 line.

The dates that matter

  1. 2020-12-10

    Flink 1.12 adds Kubernetes HA. The announcement states the ZooKeeper dependency will not be dropped.

  2. 2024-02-02

    ZooKeeper 3.7 reaches end of life.

  3. 2026-06-03

    Flink 1.20.5, marked LTS, still builds against ZooKeeper 3.7.1.

  4. 2026-06-25

    Flink 2.3.0, the latest stable release, builds against ZooKeeper 3.7.2.

  5. 2026-09-16

    Five new ZooKeeper advisories, assessed by the project only against 3.8 and 3.9.

What OSSeva delivers

1

Patched Flink 1.x builds

Security fixes backported to the Flink 1.x line you run, including shaded dependencies, shipped as signed distributions and container images. Job APIs, savepoint formats and configuration stay the same.

OSSeva PatchFlink 1.19 and earlierSigned builds & images
2

Patched ZooKeeper for Flink HA

Patched builds of the ZooKeeper ensemble that holds JobManager leader election and checkpoint pointers, and a patched flink-shaded-zookeeper so the jar inside Flink is covered too.

OSSeva PatchZooKeeper 3.7Shaded jar
3

HA review and 2.x planning

A review of your HA setup, a move to Kubernetes HA where Flink runs on Kubernetes, and a job-by-job plan for Flink 2.x. 24/7 operations for JobManagers, checkpoints and the ensemble are available.

OSSeva AssureKubernetes HAOSSeva Operate

Your options, compared

OptionWhat you getTrade-off
Move to Flink 1.20 LTSThe last community-maintained 1.x lineIt still builds against ZooKeeper 3.7.1, and the LTS ends when the community ends it.
Migrate to Flink 2.xA current release lineAPI changes and state migration for every job, and 2.3.0 still builds against ZooKeeper 3.7.2.
Switch HA to KubernetesNo ZooKeeper dependencyOnly works where Flink runs on Kubernetes. YARN and bare-metal clusters need ZooKeeper.
OSSeva extended supportPatched Flink 1.x, patched ZooKeeper and a 2.x planA subscription while the jobs move.

Support policy and release dates from flink.apache.org/downloads. HA facts from the Flink HA documentation and the Flink 1.12 announcement. Bundled ZooKeeper versions from the zookeeper.version property in Flink's root pom.xml at the release-1.19.3, release-1.20.5 and release-2.3.0 tags. CVE ranges from zookeeper.apache.org/security and NVD.

Frequently asked questions

Which Flink versions are supported?

Flink's policy is to support the current and previous minor release with bug fixes. The downloads page lists 2.3.0 as the latest stable release and marks 1.20 as the long-term support release of the 1.x line. Flink 1.19 and earlier are outside the policy.

Which ZooKeeper version does Flink use?

Flink 1.17 to 1.20, including 1.20.5, build against ZooKeeper 3.7.1. Flink 2.3.0 builds against 3.7.2. Both are on the 3.7 line, which reached end of life on 2 February 2024.

Can Flink run without ZooKeeper?

On Kubernetes, yes, using Kubernetes HA services, which Flink added in 1.12. On YARN or bare metal, high availability requires ZooKeeper.

Why does my scanner flag flink-shaded-zookeeper?

Flink ships ZooKeeper shaded under that artifact name, so scanners match it to ZooKeeper CVEs. OSSeva's patched build replaces it and comes with a VEX statement for the findings that remain.

Keep your Flink jobs running, patched.

Book a discovery call about your Flink versions, HA setup and the jobs that matter most.