// ZooKeeper dependency map

What runs on ZooKeeper?
The coordination layer nobody owns.

For well over a decade, Apache ZooKeeper was the standard way for clustered Java systems to elect a leader and share configuration, and most of them still use it. It ships inside Solr, HBase, Hadoop, Druid, NiFi, Pulsar and every Cloudera distribution, usually as a version several years older than the product around it. Four of its six release lines are end of life, and many teams only find their ensemble when a scanner flags it.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Products that depend on ZooKeeper

The oldest ZooKeeper each product has shipped, taken from the build file at each release tag or the vendor's component list. Select a product for every version, its CVE exposure and how to check what you run.

ProductZooKeeperOldest bundledNewest bundled
Apache KafkaRemoved: Removed in Kafka 4.03.5.9 in Kafka 2.8.2Line EOL 1 June 20223.8.4 in Kafka 3.6.2, 3.7.2 and 3.9.2
Apache SolrRequired: Required for SolrCloud3.4.13 in Solr 8.0.0Line EOL 1 June 20203.9.4 in Solr 10.0.0
Apache HBaseRequired: Required (server side)3.4.10 in HBase 1.7.2Line EOL 1 June 20203.8.6 in HBase 2.5.15, 2.6.6 and 3.0.0
Apache HadoopRequired: Required for HA3.4.14 in Hadoop 2.10.2Line EOL 1 June 20203.8.6 in Hadoop 3.5.0
Apache HiveOptional: Used for HA, discovery and locks3.4.6 in Hive 3.1.3Line EOL 1 June 20203.8.4 in Hive 4.2.1
Apache DruidDefault: Default; optional only experimentally3.5.9 in Druid 0.22.1Line EOL 1 June 20223.8.6 in Druid 37.0.0
ClickHouseOptional: ZooKeeper or ClickHouse KeeperExternal ensemblen/a
Apache NiFiDefault: Default for clusters3.8.0 in NiFi 1.19.13.9.3 in NiFi 1.28.1
Apache Pulsar and BookKeeperDefault: Default; Oxia available3.9.1 in Pulsar 2.10.63.9.4 in Pulsar 4.0.9
Apache StormRequired: Required3.5.9 in Storm 2.4.0Line EOL 1 June 20223.9.5 in Storm 3.1.0
Apache FlinkOptional: One of two HA options3.7.1 in Flink 1.17.2, 1.18.1 and 1.20.3Line EOL 2 February 20243.7.1 in Flink 1.17.2, 1.18.1 and 1.20.3
Patroni (PostgreSQL HA)Optional: One of several DCS optionsExternal ensemblen/a
Apache AccumuloRequired: Required3.4.14 in Accumulo 1.10.4Line EOL 1 June 20203.8.2 in Accumulo 3.0.0
Apache PinotRequired: Required (through Helix)3.9.5 in Pinot 1.5.13.9.5 in Pinot 1.5.1
Cloudera CDH, HDP and CDPRequired: Bundled in every release3.4.5 in CDH 5 (5.0 to 5.16)Line EOL 1 June 20203.8.5 in CDP 7.3.2
Apache CuratorClient libraryThe standard Java client for ZooKeeper, used by Solr, Hadoop, Hive, Druid, NiFi and Storm. Curator 5.0 dropped ZooKeeper 3.4 support; 5.9.0 is current.
Apache HelixRequiredCluster management framework that stores its state in ZooKeeper; used by Pinot.
Apache KylinRequiredKylin 5 lists ZooKeeper as a required component and uses it for service discovery in cluster mode.
VitessOne optionTopology service can be zk2, etcd2 or Consul.
Apache DubboOne optionService registry can be ZooKeeper, Nacos, Redis, Consul or etcd; optional since 3.3.0.
Apache MesosRetiredUsed ZooKeeper for master election in HA mode. Mesos was retired in August 2025 and moved to the Apache Attic in October 2025.
Apache CassandraDoes not use itCassandra uses a gossip protocol for membership and failure detection, not ZooKeeper.

Why it hides in the middle of the stack

It is half runtime, half library

ZooKeeper was built as a service, but products embed the jar or start their own server so nobody has to run an ensemble. The version comes with the product, not from a platform team.

Stable means forgotten

An ensemble that holds quorum for years raises no tickets. It sits under systems whose upgrades are planned around applications, so it drifts further behind than anything above it.

Scanners see it first

Vulnerability scanners match the ZooKeeper and Curator jars inside a product against their databases. The vendor gets the finding for a component it never chose to maintain.

ZooKeeper release lines

LineLast releaseStatus
3.43.4.14End of life 1 June 2020
3.53.5.10End of life 1 June 2022
3.63.6.4End of life 30 December 2022
3.73.7.2End of life 2 February 2024
3.83.8.7Supported
3.93.9.6Supported

Source: zookeeper.apache.org/releases. ZooKeeper 3.4.x, 3.5.0 to 3.5.9, 3.6.0 to 3.6.3 and 3.7.0 also ship log4j 1.2.17.

ZooKeeper's own CVEs

CVECVSSWhat it isFixed in
CVE-2018-80127.5No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader.3.4.10, 3.5.4-beta
CVE-2019-02015.9getACL() performs no permission check and exposes unsalted digest authentication hashes.3.4.14, 3.5.5
CVE-2023-449819.1SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.3.7.2, 3.8.3, 3.9.1
CVE-2024-239445.3Persistent watchers skip the ACL check on child znodes, leaking their paths.3.8.4, 3.9.2
CVE-2024-515049.1AdminServer IP authentication trusts X-Forwarded-For, allowing an authentication bypass.3.9.3
CVE-2025-584574.3AdminServer snapshot and restore commands run with insufficient permission checks.3.9.4
CVE-2026-242817.4TLS hostname verification falls back to reverse DNS, allowing server or client impersonation.3.8.6, 3.9.5
CVE-2026-243087.5Sensitive client configuration values are written to the log at INFO level.3.8.6, 3.9.5
CVE-2026-597397.5Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944.3.8.7, 3.9.6
CVE-2026-599697.5Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum.3.8.7, 3.9.6
CVE-2026-799937.5The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes.3.8.7, 3.9.6

Sources: zookeeper.apache.org/security and NVD. None is in CISA's Known Exploited Vulnerabilities catalog. The project does not assess end-of-life lines against new advisories.

Where coordination is going

Newer systems use Raft-based coordination instead: KRaft inside Kafka, ClickHouse Keeper, etcd under Kubernetes, Consul, and Apache Ratis as an embeddable Java library. None is a drop-in replacement. Each move is a product-specific migration, and the ensemble you retire for one product usually still serves three others.

That is why OSSeva does both: patched ZooKeeper builds that drop in with your configuration and logs unchanged, and a plan to move each product to Raft-based coordination when it is ready. Compare the alternatives.

Frequently asked questions

What is Apache ZooKeeper used for?

Coordination for distributed systems: leader election, cluster membership, configuration, locks and naming. Systems keep small pieces of shared state in ZooKeeper's tree of znodes and watch them for changes, so every node in a cluster agrees on who the leader is and what the configuration says.

Which Apache projects use ZooKeeper?

Solr (SolrCloud), HBase, Hadoop (HDFS and YARN high availability), Hive, Druid, NiFi, Pulsar and BookKeeper, Storm, Flink (ZooKeeper HA), Accumulo, Pinot through Helix, Kylin and Curator, and Kafka before 4.0. Mesos used it too before it was retired in 2025.

Does Apache Kafka still use ZooKeeper?

Not from Kafka 4.0, released in March 2025, which runs only in KRaft mode. Kafka 3.9 is the last line that can run on ZooKeeper, and it is now an archived release.

Does Cassandra use ZooKeeper?

No. Apache Cassandra uses a gossip protocol for membership and failure detection.

Is ZooKeeper still maintained?

Yes, with patch releases on two lines: 3.9.6 and 3.8.7 both shipped on 15 September 2026. There has been no new minor line since 3.9.0 in August 2023, and the current releases still bundle Jetty 9, which reached end of life in January 2025. The 3.4, 3.5, 3.6 and 3.7 lines are end of life and receive no fixes.

Why don't teams know they run ZooKeeper?

Because it arrives inside something else. Products embed the ZooKeeper jar, distributions such as CDH and HDP ship their own build, and Solr and NiFi can start an embedded server. The team that owns Kafka or Hadoop rarely owns the ensemble, so it is often the oldest component in the estate and the first thing a scanner flags.

Find the ZooKeeper in your estate before an auditor does.

Send us the products you run; we map every ensemble and embedded jar, and tell you what each is exposed to.