OSSEVA FOR APACHE DRUID
Druid moves fast. Production clusters do not.
The Druid download page lists two releases: 37.0.0 from 8 May 2026 and 36.0.0 from 9 February 2026. Everything older sits in the Apache archive with no published support window. OSSeva ships patched builds for the older releases that still run production analytics.
Trusted globally by enterprises




Why now
There is no long-term support line
Apache Druid does not publish end-of-life dates or an LTS release. The download page carries the two latest releases and points to the archive for everything else. A cluster on 25.0 or 30.0 has no published support window at all, and moving it forward means crossing several major versions, each with its own upgrade notes.
The hidden ZooKeeper time bomb
ZooKeeper is still Druid's default for cluster state and for Coordinator and Overlord leader election, and running without it needs the Kubernetes extension, which the docs mark experimental. Druid 0.22.1 and 25.0.0 bundle ZooKeeper 3.5.9, from a line that reached end of life on 1 June 2022 and still ships log4j 1.2.17. Releases 30.0.0 to 36.0.0 bundle 3.8.4. Even 37.0.0 bundles 3.8.6, inside the affected range of the ZooKeeper advisories published on 16 September 2026 and fixed in 3.8.7.
Old clusters carry old exploits
CVE-2021-25646 let an authenticated user make Druid 0.20.0 and earlier run user-supplied JavaScript, even with JavaScript disabled, and NVD scores it 8.8. Clusters never upgraded past that point still carry it. Jumping ahead is not free either: 25.0 moved segment discovery and task management from ZooKeeper to HTTP by default, and 30.0 removed ZooKeeper-based segment loading.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 0.22.x(Archived by Apache — OSSeva patched) | EOL | Clean |
| 25.x(Archived by Apache — OSSeva patched) | EOL | Clean |
| 30.x to 35.x(Archived by Apache — OSSeva patched) | EOL | Clean |
| 36.x(Previous release, 9 Feb 2026) | Extended | Clean |
| 37.x(Latest release, 8 May 2026) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed builds for archived Druid releases, bundled ZooKeeper included.
- Security backports on the Druid release you run, segments untouched
- Bundled ZooKeeper and Curator patched in the same build
- Extension and transitive dependency patching (Jetty, Jackson, Netty)
- Docker / tarball delivery
- Signed artifacts (GPG) and VEX statements for scanner findings
- Cluster security audit
- 24/7 managed operations
OSSeva Assure
Patch plus a cluster audit and a multi-version upgrade plan.
- Everything in Patch
- Coordinator, Overlord and ZooKeeper quorum review
- Authentication, authorisation and JavaScript setting audit
- Extension inventory against the target release
- SOC 2 / HIPAA attestation package with VEX for auditors
- Upgrade plan across every major version between you and 37
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 Druid monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 query latency, ingestion lag and segment load monitoring
- 15-minute P1 incident response SLA
- Named senior Druid engineer
- Compaction, retention and deep storage management
- Rolling upgrade execution with ingestion kept running
- Quarterly capacity and query cost reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# Version reported by any Druid service
curl -s http://coordinator.internal:8081/status | jq -r .version
# Current leaders, elected through ZooKeeper
curl -s http://coordinator.internal:8081/druid/coordinator/v1/leader
curl -s http://overlord.internal:8090/druid/indexer/v1/leader
# ZooKeeper settings and the jar bundled with this release
grep -E '^druid.zk.service.(host|enabled)' conf/druid/cluster/_common/common.runtime.properties
ls lib/ | grep -E '^zookeeper-[0-9]'# Same segments, same metadata store, patched binaries
docker pull artifacts.osseva.io/druid:25.0.0-osseva-1Migrate from Unsupported community Druid releases
OSSeva ships patched builds on the Druid release you already run, so segments, ingestion specs, the metadata store and extensions stay as they are, and the bundled ZooKeeper is patched in the same build. When the cluster moves forward, OSSeva plans the jump across each major version's upgrade notes and runs it as a rolling change.
Pricing model
OSSeva for Apache Druid is priced per cluster, not per node, query or ingested row.
Frequently asked questions
Does Apache Druid have an LTS release or end-of-life dates?
No. Apache Druid publishes neither. The download page lists the latest release, 37.0.0 from 8 May 2026, and the previous one, 36.0.0 from 9 February 2026, and every earlier release is in the Apache archive. OSSeva ships patched builds for those older releases today.
Is Apache Druid a database?
Yes. The project describes Druid as a high performance, real-time analytics database for sub-second queries on streaming and batch data. It runs as a set of services (Coordinator, Overlord, Broker, Historical, MiddleManager and Router) coordinated through ZooKeeper, with a separate metadata store and deep storage.
Does Druid still need ZooKeeper?
Yes, by default. Druid uses ZooKeeper for current cluster state and for Coordinator and Overlord leader election. It moved segment discovery and task management to HTTP by default in 25.0 and removed ZooKeeper-based segment loading in 30.0, but a ZooKeeper-free cluster needs the Kubernetes extension, which the Druid documentation marks as experimental.
Which ZooKeeper version does my Druid bundle?
Druid 0.22.1 and 25.0.0 bundle ZooKeeper 3.5.9, from a line that reached end of life on 1 June 2022. Releases 30.0.0 to 36.0.0 bundle 3.8.4, and 37.0.0 bundles 3.8.6. OSSeva patches the bundled ZooKeeper together with Druid.
Can OSSeva patch Druid without an upgrade?
Yes. OSSeva ships patched builds on the release you run, so segments, ingestion specs, the metadata store and extensions are untouched, and services are replaced one at a time. Start with Patch, or book a discovery call to plan the move to 37.
Ready to get Apache Druid patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.