// What runs on ZooKeeper / flink

Does Apache Flink use ZooKeeper?

One of two HA options

Flink's high availability services come in two implementations: ZooKeeper, which works with every deployment, and Kubernetes, which works only on Kubernetes. Flink 1.12 added the Kubernetes option, and the project said at the time that the ZooKeeper dependency would not be dropped. Both are still documented in Flink 2.x.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Flink uses ZooKeeper for

  • JobManager leader election.
  • Pointers to the metadata needed for recovery: job graphs and completed checkpoints.

Which ZooKeeper version ships with Apache Flink

The zookeeper.version property in Flink's root pom.xml at each release tag. Flink ships ZooKeeper shaded (flink-shaded-zookeeper), so scanners may report it under that artifact name.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Flink 1.17.2, 1.18.1 and 1.20.33.7.1End of life since 2 February 20242 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.7.1 is exposed to

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

CVE-2024-23944 · CVSS 5.3 · fixed in 3.8.4, 3.9.2

Persistent watchers skip the ACL check on child znodes, leaking their paths.

Which HA service is Flink using?

grep -E '^high-availability|zookeeper.quorum' conf/flink-conf.yaml conf/config.yaml 2>/dev/null

ls lib/ | grep -i zookeeper

Can Apache Flink run without ZooKeeper?

Yes, on Kubernetes, using Kubernetes HA services (ConfigMaps). Outside Kubernetes, HA requires ZooKeeper.

Flink 2.3.0 is the current stable release.

Your options

Switch HA to Kubernetes

On Kubernetes, Kubernetes HA removes the ZooKeeper dependency without an application change.

Patch the ZooKeeper path

Where Flink runs on YARN or bare metal, ZooKeeper HA stays. OSSeva patches the ensemble.

Most teams buy this at the product level: keep the Apache Flink estate supported, including the ZooKeeper under it. See Flink extended support.

Frequently asked questions

Which ZooKeeper does Flink 1.20 use?

Flink 1.20.3 builds against ZooKeeper 3.7.1. The 3.7 line reached end of life on 2 February 2024, and 3.7.1 is within the affected range of CVE-2023-44981 and CVE-2024-23944.

Keep Apache Flink and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.