// ZooKeeper dependency map
What runs on ZooKeeper?
The coordination layer nobody owns.
For well over a decade, Apache ZooKeeper was the standard way for clustered Java systems to elect a leader and share configuration, and most of them still use it. It ships inside Solr, HBase, Hadoop, Druid, NiFi, Pulsar and every Cloudera distribution, usually as a version several years older than the product around it. Four of its six release lines are end of life, and many teams only find their ensemble when a scanner flags it.
Trusted globally by enterprises




Products that depend on ZooKeeper
The oldest ZooKeeper each product has shipped, taken from the build file at each release tag or the vendor's component list. Select a product for every version, its CVE exposure and how to check what you run.
| Product | ZooKeeper | Oldest bundled | Newest bundled |
|---|---|---|---|
| Apache Kafka | Removed: Removed in Kafka 4.0 | 3.5.9 in Kafka 2.8.2Line EOL 1 June 2022 | 3.8.4 in Kafka 3.6.2, 3.7.2 and 3.9.2 |
| Apache Solr | Required: Required for SolrCloud | 3.4.13 in Solr 8.0.0Line EOL 1 June 2020 | 3.9.4 in Solr 10.0.0 |
| Apache HBase | Required: Required (server side) | 3.4.10 in HBase 1.7.2Line EOL 1 June 2020 | 3.8.6 in HBase 2.5.15, 2.6.6 and 3.0.0 |
| Apache Hadoop | Required: Required for HA | 3.4.14 in Hadoop 2.10.2Line EOL 1 June 2020 | 3.8.6 in Hadoop 3.5.0 |
| Apache Hive | Optional: Used for HA, discovery and locks | 3.4.6 in Hive 3.1.3Line EOL 1 June 2020 | 3.8.4 in Hive 4.2.1 |
| Apache Druid | Default: Default; optional only experimentally | 3.5.9 in Druid 0.22.1Line EOL 1 June 2022 | 3.8.6 in Druid 37.0.0 |
| ClickHouse | Optional: ZooKeeper or ClickHouse Keeper | External ensemble | n/a |
| Apache NiFi | Default: Default for clusters | 3.8.0 in NiFi 1.19.1 | 3.9.3 in NiFi 1.28.1 |
| Apache Pulsar and BookKeeper | Default: Default; Oxia available | 3.9.1 in Pulsar 2.10.6 | 3.9.4 in Pulsar 4.0.9 |
| Apache Storm | Required: Required | 3.5.9 in Storm 2.4.0Line EOL 1 June 2022 | 3.9.5 in Storm 3.1.0 |
| Apache Flink | Optional: One of two HA options | 3.7.1 in Flink 1.17.2, 1.18.1 and 1.20.3Line EOL 2 February 2024 | 3.7.1 in Flink 1.17.2, 1.18.1 and 1.20.3 |
| Patroni (PostgreSQL HA) | Optional: One of several DCS options | External ensemble | n/a |
| Apache Accumulo | Required: Required | 3.4.14 in Accumulo 1.10.4Line EOL 1 June 2020 | 3.8.2 in Accumulo 3.0.0 |
| Apache Pinot | Required: Required (through Helix) | 3.9.5 in Pinot 1.5.1 | 3.9.5 in Pinot 1.5.1 |
| Cloudera CDH, HDP and CDP | Required: Bundled in every release | 3.4.5 in CDH 5 (5.0 to 5.16)Line EOL 1 June 2020 | 3.8.5 in CDP 7.3.2 |
| Apache Curator | Client library | The standard Java client for ZooKeeper, used by Solr, Hadoop, Hive, Druid, NiFi and Storm. Curator 5.0 dropped ZooKeeper 3.4 support; 5.9.0 is current. | |
| Apache Helix | Required | Cluster management framework that stores its state in ZooKeeper; used by Pinot. | |
| Apache Kylin | Required | Kylin 5 lists ZooKeeper as a required component and uses it for service discovery in cluster mode. | |
| Vitess | One option | Topology service can be zk2, etcd2 or Consul. | |
| Apache Dubbo | One option | Service registry can be ZooKeeper, Nacos, Redis, Consul or etcd; optional since 3.3.0. | |
| Apache Mesos | Retired | Used ZooKeeper for master election in HA mode. Mesos was retired in August 2025 and moved to the Apache Attic in October 2025. | |
| Apache Cassandra | Does not use it | Cassandra uses a gossip protocol for membership and failure detection, not ZooKeeper. | |
Why it hides in the middle of the stack
It is half runtime, half library
ZooKeeper was built as a service, but products embed the jar or start their own server so nobody has to run an ensemble. The version comes with the product, not from a platform team.
Stable means forgotten
An ensemble that holds quorum for years raises no tickets. It sits under systems whose upgrades are planned around applications, so it drifts further behind than anything above it.
Scanners see it first
Vulnerability scanners match the ZooKeeper and Curator jars inside a product against their databases. The vendor gets the finding for a component it never chose to maintain.
ZooKeeper release lines
| Line | Last release | Status |
|---|---|---|
| 3.4 | 3.4.14 | End of life 1 June 2020 |
| 3.5 | 3.5.10 | End of life 1 June 2022 |
| 3.6 | 3.6.4 | End of life 30 December 2022 |
| 3.7 | 3.7.2 | End of life 2 February 2024 |
| 3.8 | 3.8.7 | Supported |
| 3.9 | 3.9.6 | Supported |
Source: zookeeper.apache.org/releases. ZooKeeper 3.4.x, 3.5.0 to 3.5.9, 3.6.0 to 3.6.3 and 3.7.0 also ship log4j 1.2.17.
ZooKeeper's own CVEs
| CVE | CVSS | What it is | Fixed in |
|---|---|---|---|
| CVE-2018-8012 | 7.5 | No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader. | 3.4.10, 3.5.4-beta |
| CVE-2019-0201 | 5.9 | getACL() performs no permission check and exposes unsalted digest authentication hashes. | 3.4.14, 3.5.5 |
| CVE-2023-44981 | 9.1 | SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true. | 3.7.2, 3.8.3, 3.9.1 |
| CVE-2024-23944 | 5.3 | Persistent watchers skip the ACL check on child znodes, leaking their paths. | 3.8.4, 3.9.2 |
| CVE-2024-51504 | 9.1 | AdminServer IP authentication trusts X-Forwarded-For, allowing an authentication bypass. | 3.9.3 |
| CVE-2025-58457 | 4.3 | AdminServer snapshot and restore commands run with insufficient permission checks. | 3.9.4 |
| CVE-2026-24281 | 7.4 | TLS hostname verification falls back to reverse DNS, allowing server or client impersonation. | 3.8.6, 3.9.5 |
| CVE-2026-24308 | 7.5 | Sensitive client configuration values are written to the log at INFO level. | 3.8.6, 3.9.5 |
| CVE-2026-59739 | 7.5 | Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944. | 3.8.7, 3.9.6 |
| CVE-2026-59969 | 7.5 | Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum. | 3.8.7, 3.9.6 |
| CVE-2026-79993 | 7.5 | The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes. | 3.8.7, 3.9.6 |
Sources: zookeeper.apache.org/security and NVD. None is in CISA's Known Exploited Vulnerabilities catalog. The project does not assess end-of-life lines against new advisories.
Where coordination is going
Newer systems use Raft-based coordination instead: KRaft inside Kafka, ClickHouse Keeper, etcd under Kubernetes, Consul, and Apache Ratis as an embeddable Java library. None is a drop-in replacement. Each move is a product-specific migration, and the ensemble you retire for one product usually still serves three others.
That is why OSSeva does both: patched ZooKeeper builds that drop in with your configuration and logs unchanged, and a plan to move each product to Raft-based coordination when it is ready. Compare the alternatives.
Frequently asked questions
What is Apache ZooKeeper used for?
Coordination for distributed systems: leader election, cluster membership, configuration, locks and naming. Systems keep small pieces of shared state in ZooKeeper's tree of znodes and watch them for changes, so every node in a cluster agrees on who the leader is and what the configuration says.
Which Apache projects use ZooKeeper?
Solr (SolrCloud), HBase, Hadoop (HDFS and YARN high availability), Hive, Druid, NiFi, Pulsar and BookKeeper, Storm, Flink (ZooKeeper HA), Accumulo, Pinot through Helix, Kylin and Curator, and Kafka before 4.0. Mesos used it too before it was retired in 2025.
Does Apache Kafka still use ZooKeeper?
Not from Kafka 4.0, released in March 2025, which runs only in KRaft mode. Kafka 3.9 is the last line that can run on ZooKeeper, and it is now an archived release.
Does Cassandra use ZooKeeper?
No. Apache Cassandra uses a gossip protocol for membership and failure detection.
Is ZooKeeper still maintained?
Yes, with patch releases on two lines: 3.9.6 and 3.8.7 both shipped on 15 September 2026. There has been no new minor line since 3.9.0 in August 2023, and the current releases still bundle Jetty 9, which reached end of life in January 2025. The 3.4, 3.5, 3.6 and 3.7 lines are end of life and receive no fixes.
Why don't teams know they run ZooKeeper?
Because it arrives inside something else. Products embed the ZooKeeper jar, distributions such as CDH and HDP ship their own build, and Solr and NiFi can start an embedded server. The team that owns Kafka or Hadoop rarely owns the ensemble, so it is often the oldest component in the estate and the first thing a scanner flags.
Find the ZooKeeper in your estate before an auditor does.
Send us the products you run; we map every ensemble and embedded jar, and tell you what each is exposed to.