OSSEVA FOR APACHE STORM
Storm 2.x is end of life. Storm 3 needs Java 25.
Storm 2.8.9, released on 22 July 2026, was the final 2.x release. When 3.1.0 shipped on 12 September 2026 with a set of security fixes, the project told 2.x users to treat those issues as unpatched on 2.x. OSSeva ships patched 2.x builds today.
Trusted globally by enterprises




Why now
The 2.x line has stopped
The Storm project released 3.0.0 and 2.8.9 together on 22 July 2026 and called 2.8.9 the final release of the 2.x line. The 3.1.0 announcement on 12 September 2026 resolved a coordinated set of security issues and stated that 2.x no longer receives security fixes. The 1.x line has had no release since 1.2.4 in October 2021.
Storm 3 is a Java 25 migration
Storm 3.x requires Java 25 to run. The Java API stays backwards compatible with 2.x, but every topology, its dependencies and the images underneath move to a new JVM at the same time. For topologies built years ago against older libraries, that is the hard part of the upgrade, and it rarely fits in one maintenance window.
The hidden ZooKeeper time bomb
Every Storm release requires ZooKeeper for coordination between Nimbus and the supervisors. Storm 1.2.4 bundles ZooKeeper 3.4.14 and 2.4.0 bundles 3.5.9, both from end-of-life lines. Even 2.8.9 and 3.1.0 bundle 3.9.5, inside the affected range of the ZooKeeper advisories published on 16 September 2026. The credential matters as much as the version: Storm's own CVE-2026-82434 had Nimbus serving a topology's write-capable ZooKeeper credential to read-only users.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 1.2.x(No release since Oct 2021 — OSSeva patched) | EOL | Clean |
| 2.4.x(Community EOL 22 Jul 2026 — OSSeva patched) | EOL | Clean |
| 2.6.x(Community EOL 22 Jul 2026 — OSSeva patched) | EOL | Clean |
| 2.7.x(Community EOL 22 Jul 2026 — OSSeva patched) | EOL | Clean |
| 2.8.x(Community EOL 22 Jul 2026 — OSSeva patched) | EOL | Clean |
| 3.x(3.1.0 released 12 Sep 2026, Java 25) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed Storm 1.2 and 2.x builds on the Java you already run.
- Security backports for 1.2 and 2.x, topologies unchanged
- Bundled ZooKeeper and Curator patched in the same build
- Transitive dependency patching (Netty, Jetty, Jackson, Kryo)
- Maven / Docker / tarball delivery
- Signed artifacts (GPG) and VEX statements for scanner findings
- Nimbus, UI and ZooKeeper security audit
- 24/7 managed operations
OSSeva Assure
Patch plus a cluster audit and a Java 25 migration plan.
- Everything in Patch
- Nimbus HA, supervisor and ZooKeeper quorum review
- nimbus.users, nimbus.groups and ZooKeeper credential audit
- Topology and dependency inventory against Java 25
- SOC 2 / HIPAA attestation package with VEX for auditors
- Upgrade plan to Storm 3.1
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 topology monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 throughput, latency and back-pressure monitoring
- 15-minute P1 incident response SLA
- Named senior Storm engineer
- Topology deployment and rebalance management
- Storm 3 and Java 25 migration execution
- Quarterly capacity reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# Storm version on this node
storm version | head -1
# Cluster version from the Storm UI REST API
curl -s http://storm-ui.internal:8080/api/v1/cluster/summary | jq -r .stormVersion
# The ensemble Nimbus and the supervisors coordinate through
grep -A3 storm.zookeeper.servers $STORM_HOME/conf/storm.yaml
# ZooKeeper jar bundled with this Storm
ls $STORM_HOME/lib/ | grep -E '^zookeeper-[0-9]'<dependency>
<groupId>io.osseva.storm</groupId>
<artifactId>storm-client</artifactId>
<version>2.8.9-osseva-1</version>
</dependency>Migrate from Unsupported Storm 1.x and 2.x clusters
OSSeva ships patched builds on the Storm line you already run, so topologies, serialisers and the JVM stay as they are, and the bundled ZooKeeper is patched in the same build. When the move to Storm 3.1 is due, OSSeva plans the Java 25 migration topology by topology and runs the cutover.
Pricing model
OSSeva for Apache Storm is priced per cluster, not per topology or per worker.
Frequently asked questions
Is Apache Storm 2.x end of life?
Yes. Storm 2.8.9, released on 22 July 2026 alongside 3.0.0, was the final 2.x release, and the branch is no longer maintained. The 3.1.0 announcement on 12 September 2026 stated that 2.x no longer receives security fixes.
What does Storm 3 require?
Java 25. The Storm 3.x Java API remains backwards compatible with 2.x, so topology code written against 2.x carries over, but every topology and its dependencies have to run on the new JVM. Storm 3.1.0 still requires ZooKeeper.
Does Storm still need ZooKeeper?
Yes, in every version. The Storm 3.1.0 cluster setup guide makes a ZooKeeper cluster step one, and storm.zookeeper.servers is mandatory configuration. Nimbus and the supervisors coordinate through it, and topology assignment state lives there.
Which ZooKeeper version does my Storm bundle?
Storm 1.2.4 bundles ZooKeeper 3.4.14, 2.4.0 bundles 3.5.9, 2.6.4 bundles 3.9.2, 2.7.1 bundles 3.9.3, and 2.8.9 and 3.1.0 bundle 3.9.5. OSSeva patches the bundled ZooKeeper together with Storm.
Can we stay on Storm 2.x and remain supported?
Yes. OSSeva ships patched Storm 2.x builds today, on the Java version you already run, with topologies unchanged. Start with Patch, and talk to an engineer when the Java 25 migration is on the table.
Ready to get Apache Storm patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.