// Apache HBase extended support
Still running HBase 1.x or 2.4?
The community has stopped patching them. OSSeva has not.
The HBase Reference Guide marks 1.x and 2.0 to 2.4 as end of maintenance. The last 1.x release, 1.7.2, shipped in August 2022, and the last 2.4 release, 2.4.18, in May 2024. Every HBase cluster also depends on a ZooKeeper ensemble, and the one bundled with 1.7.2 is 3.4.10, from a line that reached end of life in June 2020. OSSeva ships patched, signed HBase builds for these lines today and patches the ZooKeeper under them in the same support tier.
Trusted globally by enterprises




Why HBase clusters stay on old lines
HBase holds data that applications read in place. Moving it is rarely a quick job.
End of maintenance means no fixes
HBase 2.5 and 2.6 are the active lines. The project marked 1.x end of life in September 2022 and 2.4 in July 2024, so a new advisory against either line gets no community patch release.
The ZooKeeper underneath is older still
HBase 1.7.2 bundles ZooKeeper 3.4.10. The 3.4 line never received a fix for CVE-2023-44981, the SASL quorum authentication bypass scored 9.1, and it ships log4j 1.2.17. HBase 2.4.18 bundles ZooKeeper 3.8.4, which predates the fixes for CVE-2026-24281 and CVE-2026-24308 that arrived in 3.8.6.
Upgrades travel with the platform
Many HBase clusters sit inside a Hadoop distribution, so moving to 2.5 or 2.6 means upgrading HDFS and the rest of the platform too. HBase 3.0 moved client lookups off ZooKeeper by default, but masters and region servers still depend on it.
The dates that matter
2020-06-01
ZooKeeper 3.4 end of life. HBase 1.7.2 bundles 3.4.10.
2022-03-17
HBase 2.3 end of maintenance announced.
2022-08-09
HBase 1.7.2 released, the last 1.x release. The project marks 1.x end of life in September 2022.
2024-05-25
HBase 2.4.18 released, the last 2.4 release. The project marks 2.4 end of life in July 2024.
2026-08-05
HBase 3.0.0 released. Masters and region servers still require ZooKeeper.
2026-09-16
Five ZooKeeper advisories fixed in 3.8.7. Current HBase 2.5, 2.6 and 3.0 releases bundle 3.8.6.
What OSSeva delivers
Patched HBase 1.x and 2.x builds
Security fixes backported to the HBase line you run, from 1.7 to 2.4, built from upstream source and delivered as signed tarballs, Maven artifacts and container images through your own repository.
The ZooKeeper under HBase
Patched builds for the ensemble HBase depends on, whether it is the bundled 3.4.10 or an external 3.4, 3.5, 3.6 or 3.7 ensemble, with configuration and data unchanged. VEX statements cover the jar your scanner flags.
Upgrade to 2.5, 2.6 or 3.0
A tested path from the patched line to an active one, covering Hadoop compatibility, the client registry change in 3.0 and a rollback plan for each step.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade to HBase 2.5 or 2.6 | Active community lines with a ZooKeeper 3.8 client | Often a Hadoop platform upgrade as well, planned and tested cluster by cluster. |
| Move to a commercial distribution | Vendor support for a current HBase | A platform migration and a new subscription. |
| OSSeva extended support | Patched HBase and ZooKeeper now, and the upgrade when you are ready | A subscription for as long as you keep the old line. |
| Stay unpatched | Nothing | New HBase and ZooKeeper advisories stay open, and scanners flag the version every week. |
Release lines from the HBase Reference Guide and downloads page. Release and end-of-life dates from the HBase JIRA and the dev@hbase.apache.org announcements. Bundled ZooKeeper versions from the root pom.xml at each release tag.
Frequently asked questions
Is HBase 2.4 end of life?
Yes. The HBase Reference Guide lists 2.4 as end of maintenance, and the project marked it end of life in July 2024. The last release was 2.4.18 on 25 May 2024. The active lines are 2.5 and 2.6, and 3.0.0 was released in August 2026.
Who provides HBase support after end of life?
Commercial distributions support the HBase versions they ship on their current platforms. OSSeva supports community HBase 1.x and 2.0 to 2.4 as they are, with patched, signed builds available today and the ZooKeeper underneath included.
Does OSSeva patch the ZooKeeper that HBase uses?
Yes. Patched builds for ZooKeeper 3.4, 3.5, 3.6 and 3.7 ship today, and 3.8 and 3.9 are supported as well. An HBase cluster is only as patched as its ensemble.
Does HBase 3.0 remove ZooKeeper?
No. HBase 3.0 makes RpcConnectionRegistry the default, so clients no longer need ZooKeeper to find hbase:meta. Masters and region servers still require it.
Which support tier fits an HBase cluster?
Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.
Keep HBase patched while the upgrade waits.
Start with Patch today. Add Assure or Operate when the cluster needs them.