// What runs on ZooKeeper / druid
Does Apache Druid use ZooKeeper?
Default; optional only experimentallyYes. Druid uses ZooKeeper for current cluster state, including Coordinator and Overlord leader election. Druid has moved segment discovery and task management to HTTP (the default since 25.0) and removed ZooKeeper-based segment loading in 30.0, but running entirely without ZooKeeper needs the Kubernetes extension, which the docs mark as experimental.
Trusted globally by enterprises




What Apache Druid uses ZooKeeper for
- Coordinator and Overlord leader election.
- Cluster membership and current cluster state.
- Historical and task announcements in older configurations (moved to HTTP by default in 25.0).
Which ZooKeeper version ships with Apache Druid
From the zookeeper.version property in pom.xml at each release tag.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| Druid 0.22.1 | 3.5.9 | End of life since 1 June 2022Bundles log4j 1.2.17 | 1 (CVE-2023-44981)2026 advisories not assessed for this line |
| Druid 25.0.0 | 3.5.9 | End of life since 1 June 2022Bundles log4j 1.2.17 | 1 (CVE-2023-44981)2026 advisories not assessed for this line |
| Druid 37.0.0 | 3.8.6 | Supported (latest 3.8.7) | 3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.5.9 is exposed to
CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1
SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.
Find the ZooKeeper Druid is using
grep -E '^druid.zk.service.(host|enabled)' conf/druid/cluster/_common/common.runtime.properties ls lib/ | grep -E '^zookeeper-[0-9]'
Can Apache Druid run without ZooKeeper?
Only on Kubernetes, through the druid-kubernetes-extensions module (druid.zk.service.enabled=false, druid.discovery.type=k8s), which the Druid documentation labels experimental.
Druid 37.0.0 (May 2026) is the latest release.
Your options
Upgrade Druid
Recent Druid releases bundle ZooKeeper 3.8.6. Druid 25 still ships 3.5.9, from a line that reached end of life in June 2022 and still carries log4j 1.2.17.
Patch the ensemble
OSSeva patches the ZooKeeper ensemble under older Druid clusters while the upgrade is planned.
Most teams buy this at the product level: keep the Apache Druid estate supported, including the ZooKeeper under it. See Apache Druid support.
Frequently asked questions
Has Druid removed ZooKeeper?
No. ZooKeeper is still the default. Druid removed specific ZooKeeper uses (segment loading, and ZooKeeper-based discovery defaults), but a ZooKeeper-free cluster requires the experimental Kubernetes extension.
Keep Apache Druid and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.