// Apache ZooKeeper extended support
There is a ZooKeeper in the middle of your stack.
It is probably end of life.
ZooKeeper coordinates Kafka, Solr, HBase, Hadoop, Hive, Druid, NiFi and Pulsar, and it usually arrives inside them rather than on anyone's roadmap. Four of its six release lines are past end of life, and the versions products actually ship, such as 3.4.6 in HDP, 3.6.3 in Kafka 3.0 to 3.3 and 3.7.1 in Flink 1.20, sit on those lines. OSSeva ships patched drop-in builds with your configuration and logs unchanged, and puts its name to the attestation your auditor asks for.
Trusted globally by enterprises




Why ZooKeeper is the component nobody upgrades
ZooKeeper is half runtime and half library. That is what makes it easy to embed and hard to own.
It ships inside the product
Kafka, Solr, HBase and every Cloudera distribution bundle their own ZooKeeper, and software vendors embed the jar in their own products. The version is chosen by whoever built the product, often years ago, and customers inherit it.
End-of-life lines get no fixes
CVE-2023-44981, a SASL quorum authentication bypass scored 9.1, was fixed in 3.7.2, 3.8.3 and 3.9.1, with nothing for 3.4, 3.5 or 3.6. CVE-2024-23944 has no fix for 3.6 or 3.7. The project does not assess end-of-life lines against new advisories at all.
Upgrading ZooKeeper means upgrading the product
Clients, Curator versions and product-level customisations are tied to the ZooKeeper line. For a software vendor, moving to a new major line can take quarters of refactoring per product version, while customers' scanners flag the old jar every week.
The dates that matter
2020-06-01
ZooKeeper 3.4 end of life. CDH 5 and 6 and HDP 2 and 3 all ship 3.4.x.
2022-06-01
ZooKeeper 3.5 end of life.
2022-12-30
ZooKeeper 3.6 end of life.
2023-10-11
CVE-2023-44981 published. No fix for 3.4, 3.5 or 3.6.
2024-02-02
ZooKeeper 3.7 end of life.
2025-03-18
Kafka 4.0 removes ZooKeeper. Solr, HBase, Hadoop, Druid, NiFi and Pulsar still use it.
2026-09-16
Five new ZooKeeper advisories, assessed only against 3.8 and 3.9.
What OSSeva delivers
Patched drop-in builds
Security fixes backported to the ZooKeeper line you run, built from the upstream source. Configuration, data format and log output stay the same, so the jar or the ensemble swaps in place.
CVE attestation for auditors
A written, third-party assessment of each flagged CVE against your architecture: fixed, not present, or not reachable in your configuration, with the evidence. Delivered in a form your auditor and your customers' auditors can file, including VEX.
Product-level support and a path to Raft
Support for the Kafka, Solr, HBase or Hadoop estate the ensemble serves, and a plan to move each product to Raft-based coordination (KRaft, ClickHouse Keeper, etcd) when it is ready.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade the product | A supported ZooKeeper client and server line | Usually a platform upgrade, and for software vendors a refactor per supported product version. |
| Write your own justification | A document explaining why each CVE does not apply | It works until one auditor rejects a vendor's self-assessment. Many do. |
| Move coordination to Raft | KRaft, ClickHouse Keeper or etcd where the product supports it | Product-specific, and the shared ensemble often still serves other systems. |
| OSSeva extended support | Patched drop-in builds, third-party attestation, and the migration plan | A subscription for as long as you need the runway. |
Dates and CVE ranges from zookeeper.apache.org (releases and security pages), NVD, and the build files of each product at its release tags.
Frequently asked questions
Which ZooKeeper versions does OSSeva patch?
All four end-of-life lines: 3.4, 3.5, 3.6 and 3.7, available now as signed drop-in builds. We also support 3.8 and 3.9, and regression-test builds against products that carry their own ZooKeeper customisations.
Will a patched jar pass our scanner?
A patched build no longer matches the vulnerable version in the scanner's database, so the old finding disappears, but some scanners then report an unrecognised component. We ship each build with the documentation that closes that gap: what changed, which CVEs are fixed, and a VEX statement.
We ship ZooKeeper inside our own product. Can you help?
Yes. That is the most common case: a software vendor with an embedded ZooKeeper and customers whose audits flag it. We deliver drop-in jars that work with your existing customisations after regression testing, and attestation your customers can hand to their auditors while you plan the upgrade.
Do you replace ZooKeeper with Raft?
When the product supports it. Kafka has KRaft and ClickHouse has Keeper; others need a product-specific plan. We patch the ensemble for the interim and plan each move.
Is ZooKeeper 3.7 end of life?
Yes, since 2 February 2024. 3.6 ended on 30 December 2022, 3.5 on 1 June 2022 and 3.4 on 1 June 2020. Only 3.8 and 3.9 receive fixes.
Find the ZooKeeper in your estate before an auditor does.
Book a call and get patched builds, an exposure map and a proposal within five working days.