// Apache HBase extended support

Still running HBase 1.x or 2.4?
The community has stopped patching them. OSSeva has not.

The HBase Reference Guide marks 1.x and 2.0 to 2.4 as end of maintenance. The last 1.x release, 1.7.2, shipped in August 2022, and the last 2.4 release, 2.4.18, in May 2024. Every HBase cluster also depends on a ZooKeeper ensemble, and the one bundled with 1.7.2 is 3.4.10, from a line that reached end of life in June 2020. OSSeva ships patched, signed HBase builds for these lines today and patches the ZooKeeper under them in the same support tier.

HBase 2.42.32.22.12.01.71.xZooKeeper 3.4 to 3.8

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why HBase clusters stay on old lines

HBase holds data that applications read in place. Moving it is rarely a quick job.

End of maintenance means no fixes

HBase 2.5 and 2.6 are the active lines. The project marked 1.x end of life in September 2022 and 2.4 in July 2024, so a new advisory against either line gets no community patch release.

The ZooKeeper underneath is older still

HBase 1.7.2 bundles ZooKeeper 3.4.10. The 3.4 line never received a fix for CVE-2023-44981, the SASL quorum authentication bypass scored 9.1, and it ships log4j 1.2.17. HBase 2.4.18 bundles ZooKeeper 3.8.4, which predates the fixes for CVE-2026-24281 and CVE-2026-24308 that arrived in 3.8.6.

Upgrades travel with the platform

Many HBase clusters sit inside a Hadoop distribution, so moving to 2.5 or 2.6 means upgrading HDFS and the rest of the platform too. HBase 3.0 moved client lookups off ZooKeeper by default, but masters and region servers still depend on it.

The dates that matter

  1. 2020-06-01

    ZooKeeper 3.4 end of life. HBase 1.7.2 bundles 3.4.10.

  2. 2022-03-17

    HBase 2.3 end of maintenance announced.

  3. 2022-08-09

    HBase 1.7.2 released, the last 1.x release. The project marks 1.x end of life in September 2022.

  4. 2024-05-25

    HBase 2.4.18 released, the last 2.4 release. The project marks 2.4 end of life in July 2024.

  5. 2026-08-05

    HBase 3.0.0 released. Masters and region servers still require ZooKeeper.

  6. 2026-09-16

    Five ZooKeeper advisories fixed in 3.8.7. Current HBase 2.5, 2.6 and 3.0 releases bundle 3.8.6.

What OSSeva delivers

1

Patched HBase 1.x and 2.x builds

Security fixes backported to the HBase line you run, from 1.7 to 2.4, built from upstream source and delivered as signed tarballs, Maven artifacts and container images through your own repository.

1.7 to 2.4Signed buildsAvailable now
2

The ZooKeeper under HBase

Patched builds for the ensemble HBase depends on, whether it is the bundled 3.4.10 or an external 3.4, 3.5, 3.6 or 3.7 ensemble, with configuration and data unchanged. VEX statements cover the jar your scanner flags.

ZooKeeper 3.4 to 3.7Drop-inVEX
3

Upgrade to 2.5, 2.6 or 3.0

A tested path from the patched line to an active one, covering Hadoop compatibility, the client registry change in 3.0 and a rollback plan for each step.

2.5 and 2.63.0Rolling upgrade

Your options, compared

OptionWhat you getTrade-off
Upgrade to HBase 2.5 or 2.6Active community lines with a ZooKeeper 3.8 clientOften a Hadoop platform upgrade as well, planned and tested cluster by cluster.
Move to a commercial distributionVendor support for a current HBaseA platform migration and a new subscription.
OSSeva extended supportPatched HBase and ZooKeeper now, and the upgrade when you are readyA subscription for as long as you keep the old line.
Stay unpatchedNothingNew HBase and ZooKeeper advisories stay open, and scanners flag the version every week.

Release lines from the HBase Reference Guide and downloads page. Release and end-of-life dates from the HBase JIRA and the dev@hbase.apache.org announcements. Bundled ZooKeeper versions from the root pom.xml at each release tag.

Frequently asked questions

Is HBase 2.4 end of life?

Yes. The HBase Reference Guide lists 2.4 as end of maintenance, and the project marked it end of life in July 2024. The last release was 2.4.18 on 25 May 2024. The active lines are 2.5 and 2.6, and 3.0.0 was released in August 2026.

Who provides HBase support after end of life?

Commercial distributions support the HBase versions they ship on their current platforms. OSSeva supports community HBase 1.x and 2.0 to 2.4 as they are, with patched, signed builds available today and the ZooKeeper underneath included.

Does OSSeva patch the ZooKeeper that HBase uses?

Yes. Patched builds for ZooKeeper 3.4, 3.5, 3.6 and 3.7 ship today, and 3.8 and 3.9 are supported as well. An HBase cluster is only as patched as its ensemble.

Does HBase 3.0 remove ZooKeeper?

No. HBase 3.0 makes RpcConnectionRegistry the default, so clients no longer need ZooKeeper to find hbase:meta. Masters and region servers still require it.

Which support tier fits an HBase cluster?

Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.

Keep HBase patched while the upgrade waits.

Start with Patch today. Add Assure or Operate when the cluster needs them.