OSSEVA FOR APACHE FLINK

Your Flink jobs are stable. The ZooKeeper inside them is end of life.

Streaming jobs carry state, savepoints and connector versions that make every Flink upgrade a project. Most clusters stay on the 1.x release they launched with, and each of those builds ships a ZooKeeper line that upstream stopped patching. OSSeva patched builds for Flink 1.x are available now.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

Flink supports two minor releases and an LTS

Since March 2017 the community has supported the current and previous minor release. Since March 2023 a minor that loses support gets one final bugfix release, and then nothing. Flink 2.3.0 is the latest release and 1.20 is labelled LTS. Flink 1.19 had its last release, 1.19.3, on 10 July 2025. 1.18, 1.17 and older ended earlier.

The ZooKeeper inside Flink is a time bomb

Flink 1.17 to 1.20 build against ZooKeeper 3.7.1, and 1.15 and 1.16 against 3.5.9. Both lines are end of life: 3.5 since 1 June 2022 and 3.7 since 2 February 2024. ZooKeeper 3.7.1 is in the affected range of CVE-2023-44981, a critical SASL quorum authentication bypass, and CVE-2024-23944. Flink shades it as flink-shaded-zookeeper, so scanners report it under a name most teams do not recognise.

Flink 2.0 is a rewrite of your job code, not a version bump

Flink 2.0 removed the DataSet API, the Scala DataStream and DataSet APIs, SourceFunction, SinkFunction and Sink V1, and the legacy TableSource and TableSink interfaces. Java 8 is no longer supported and Java 17 is the default. Jobs written against those APIs have to be ported and their state carried across before they can run on 2.x.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
1.15.x, 1.16.x(Last releases 1.15.4, 1.16.3. Bundles ZK 3.5.9. OSSeva patched)EOLClean
1.17.x(Last release 1.17.2, 29 Nov 2023. OSSeva patched)EOLClean
1.18.x(Last release 1.18.1, 19 Jan 2024. OSSeva patched)EOLClean
1.19.x(Last release 1.19.3, 10 Jul 2025. OSSeva patched)EOLClean
1.20.x (LTS)(Upstream LTS (1.20.5). Bundles EOL ZK 3.7.1)ExtendedClean
2.x(2.3.0 released 25 Jun 2026. Upstream maintained)CurrentClean

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Patched, signed builds for Flink 1.19 and older, with the bundled ZooKeeper fixed too.

  • Security backports for Flink 1.15 to 1.19, savepoint format unchanged
  • Patched flink-shaded-zookeeper in every build
  • Transitive dependency patching (Netty, Jackson, logging)
  • Maven / Docker / tarball delivery
  • Signed artifacts (GPG)
  • Flink 2.x migration plan
  • 24/7 managed operations
Get started →
Most popular

OSSeva Assure

Patch plus an HA and dependency audit, and a plan for the move to 2.x.

  • Everything in Patch
  • High availability review: ZooKeeper or Kubernetes HA
  • ZooKeeper ensemble ACL, SASL and exposure audit
  • Inventory of removed 2.x APIs used by each job
  • SOC 2 / HIPAA attestation package, including VEX for scanner findings
  • Upgrade plan to 1.20 LTS or 2.x with savepoint compatibility checks
  • 24/7 managed operations
Get started →

OSSeva Operate

Full MSP: 24/7 job monitoring, 15-min SLA, named engineers.

  • Everything in Assure
  • 24/7 checkpoint, backpressure and JobManager failover monitoring
  • 15-minute P1 incident response SLA
  • Named senior Flink engineer
  • Savepoint management and job redeployment
  • Move from ZooKeeper HA to Kubernetes HA where you run on Kubernetes
  • Staged 2.x migration execution, job by job
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Which HA service, and which ZooKeeper?bash
# ZooKeeper HA if high-availability is set to zookeeper
grep -E '^high-availability|zookeeper.quorum' \
  conf/flink-conf.yaml conf/config.yaml 2>/dev/null

# The shaded ZooKeeper that ships with this Flink build
ls lib/ opt/ | grep -i zookeeper

# Version of the ensemble Flink points at
echo srvr | nc zk1.internal 2181 | head -1
Docker: OSSeva Flinkbash
# Same Flink line, same savepoint format, patched ZooKeeper inside
docker pull artifacts.osseva.io/flink:1.19.3-osseva-1

docker run -d --name jobmanager \
  -p 8081:8081 \
  artifacts.osseva.io/flink:1.19.3-osseva-1 jobmanager

Migrate from Unsupported community Flink 1.x

OSSeva ships patched Flink builds on the 1.x line you already run, so job code, savepoints and connectors stay as they are while the cluster becomes secure. The bundled ZooKeeper and the ensemble it talks to are patched in the same build cycle. The move to 1.20 LTS or 2.x is then planned job by job, rather than forced by a scanner report.

↗

Pricing model

OSSeva for Apache Flink is priced per cluster, not per TaskManager, slot or job.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Which Apache Flink versions are still supported?

The community supports the current and previous minor release, and a minor that drops out of support gets one final bugfix release. Flink 2.3.0, released on 25 June 2026, is the latest. Flink 1.20 is labelled LTS on the project site, with 1.20.5 released on 3 June 2026. Flink 1.19 and older no longer receive community fixes.

Which ZooKeeper version does Flink bundle?

From the zookeeper.version property in Flink's pom.xml at each release tag: 3.5.9 for Flink 1.15 and 1.16, 3.7.1 for 1.17 to 1.20, and 3.7.2 for 2.0 to 2.3. ZooKeeper 3.5 reached end of life on 1 June 2022 and 3.7 on 2 February 2024, so every one of those builds carries an end-of-life ZooKeeper.

Can I run Flink without ZooKeeper?

On Kubernetes, yes. Flink 1.12 added Kubernetes HA services, which use ConfigMaps for leader election and recovery metadata. On YARN or standalone clusters, high availability still needs a ZooKeeper quorum. Both options are documented in current Flink releases.

Why not just upgrade to Flink 2.x?

Because 2.0 removed APIs that many production jobs are built on: DataSet, the Scala APIs, SourceFunction and SinkFunction, and the legacy table source and sink interfaces. It also dropped Java 8. Porting those jobs and carrying their state across is real engineering work. Patched 1.x builds keep the cluster secure while that work happens.

Our scanner flags flink-shaded-zookeeper. What does OSSeva do about it?

OSSeva builds replace the shaded ZooKeeper with a patched one, so the finding is fixed rather than suppressed. Where a reported CVE does not apply to the way Flink uses the ZooKeeper client, the Assure tier supplies a VEX statement your auditors can file.

Ready to get Apache Flink patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.