// What runs on ZooKeeper / hbase
Does Apache HBase use ZooKeeper?
Required (server side)Yes. A distributed HBase install depends on a running ZooKeeper ensemble, which HBase can manage itself or use externally. HBase 3.0 moved the client connection registry off ZooKeeper by default, but the servers still require it, and the issue to remove ZooKeeper from client connections is targeted at HBase 4.
Trusted globally by enterprises




What Apache HBase uses ZooKeeper for
- Master election and region server tracking.
- Cluster coordination state and table state transitions.
- Client bootstrap in older releases: clients found hbase:meta through ZooKeeper. HBase 2.5 added RpcConnectionRegistry, which is the default in 3.0.
Which ZooKeeper version ships with Apache HBase
From the zookeeper.version property in the root pom.xml at each release tag. Set HBASE_MANAGES_ZK=false to run an external ensemble.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| HBase 1.7.2 | 3.4.10 | End of life since 1 June 2020Bundles log4j 1.2.17 | 2 (CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| HBase 2.4.18 | 3.8.4 | Supported (latest 3.8.7) | 5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
| HBase 2.5.15, 2.6.6 and 3.0.0 | 3.8.6 | Supported (latest 3.8.7) | 3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.4.10 is exposed to
CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5
getACL() performs no permission check and exposes unsalted digest authentication hashes.
CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1
SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.
Find the ZooKeeper HBase is using
# Bundled client jar ls lib/ | grep -E '^zookeeper-[0-9]' # Is HBase managing its own ensemble? grep HBASE_MANAGES_ZK conf/hbase-env.sh # Ensemble address grep -A1 hbase.zookeeper.quorum conf/hbase-site.xml
Can Apache HBase run without ZooKeeper?
No. HBase 3.0 reduced what clients need from ZooKeeper, but region servers and masters still coordinate through it. Work to reduce the dependency further is open for HBase 4.
HBase 2.5 and 2.6 are the active lines, and 3.0.0 shipped in August 2026. The reference guide marks 2.4 and everything older as end of maintenance.
Your options
Upgrade HBase
Move to 2.5 or 2.6, which bundle ZooKeeper 3.8.6. For estates inside a Cloudera or Hortonworks distribution, the HBase upgrade usually means a platform upgrade.
Patch in place
OSSeva ships patched HBase builds for 1.x and 2.4 and patches the ZooKeeper ensemble under them, so an HBase 1.x or 2.4 cluster behind a legacy application stays supported while the platform decision is made.
Most teams buy this at the product level: keep the Apache HBase estate supported, including the ZooKeeper under it. See HBase extended support.
Frequently asked questions
Does HBase 3.0 still need ZooKeeper?
Yes on the server side. HBase 3.0 makes RpcConnectionRegistry the default for clients, so applications no longer need ZooKeeper to find hbase:meta, but masters and region servers still depend on it.
Which ZooKeeper version does HBase 1.7 use?
HBase 1.7.2 bundles ZooKeeper 3.4.10. The 3.4 line reached end of life on 1 June 2020.
Should HBase manage its own ZooKeeper?
For production, most teams run an external ensemble (HBASE_MANAGES_ZK=false) so ZooKeeper can be upgraded and monitored independently of HBase restarts.
Keep Apache HBase and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.