// What runs on ZooKeeper / hadoop

Does Apache Hadoop use ZooKeeper?

Required for HA

For high availability, yes. HDFS automatic NameNode failover adds a ZooKeeper quorum and the ZKFailoverController process, and YARN ResourceManager HA uses a ZooKeeper-based elector and, by recommendation, the ZooKeeper state store. A cluster without HA can run without ZooKeeper, but almost no production cluster does.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Hadoop uses ZooKeeper for

  • HDFS: active NameNode election and failure detection through the ZKFailoverController (ZKFC).
  • YARN: ResourceManager leader election through the embedded ActiveStandbyElector.
  • YARN: ZKRMStateStore, the recommended state store for ResourceManager HA.

Which ZooKeeper version ships with Apache Hadoop

From hadoop-project/pom.xml at each release tag. Distributions (CDH, HDP, CDP) ship their own ZooKeeper builds; see the Cloudera page.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Hadoop 2.10.23.4.14End of life since 1 June 2020Bundles log4j 1.2.171 (CVE-2023-44981)2026 advisories not assessed for this line
Hadoop 3.3.63.6.3End of life since 30 December 2022Bundles log4j 1.2.172 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line
Hadoop 3.4.03.8.3Supported (latest 3.8.7)6 (CVE-2024-23944, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Hadoop 3.4.1 to 3.4.33.8.4Supported (latest 3.8.7)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Hadoop 3.5.03.8.6Supported (latest 3.8.7)3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.4.14 is exposed to

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

Find the ZooKeeper Hadoop is using

# ZKFC and RM HA both point at this quorum
hdfs getconf -confKey ha.zookeeper.quorum
grep -A1 yarn.resourcemanager.zk-address etc/hadoop/yarn-site.xml

# Bundled client jar
ls share/hadoop/common/lib/ | grep -E '^zookeeper-[0-9]'

Can Apache Hadoop run without ZooKeeper?

Only without automatic failover. Manual NameNode failover works without ZooKeeper, and YARN can run a single ResourceManager, but both remove the high availability the cluster was designed around.

Hadoop 3.5.0 (April 2026) and 3.4.3 are the current releases.

Your options

Upgrade Hadoop or the distribution

Upstream 3.4 and 3.5 bundle supported ZooKeeper 3.8 clients. Inside CDH or HDP, the equivalent is a move to Cloudera's current platform or off Hadoop altogether.

Patch the coordination layer

OSSeva ships patched Hadoop builds for end-of-life lines and patches the ZooKeeper ensemble that HDFS and YARN HA depend on.

Most teams buy this at the product level: keep the Apache Hadoop estate supported, including the ZooKeeper under it. See Hadoop extended support.

Frequently asked questions

What is ZKFC in Hadoop?

The ZKFailoverController. It runs next to each NameNode, monitors its health, and uses a ZooKeeper lock to decide which NameNode is active during automatic failover.

Which ZooKeeper does Hadoop 3.3 use?

Hadoop 3.3.6 bundles ZooKeeper 3.6.3. That line reached end of life on 30 December 2022, and 3.6.3 still ships log4j 1.2.17.

Keep Apache Hadoop and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.