// What runs on ZooKeeper / kafka
Does Apache Kafka use ZooKeeper?
Removed in Kafka 4.0Every Kafka release before 4.0 can run on ZooKeeper, and until KRaft became production ready in 3.3 it had to. Kafka 4.0 (March 2025) removed ZooKeeper mode entirely. The last ZooKeeper-capable line is 3.9, and its final release, 3.9.2, shipped on 21 February 2026.
Trusted globally by enterprises




What Apache Kafka uses ZooKeeper for
- Broker registration and liveness: each broker holds an ephemeral znode.
- Controller election: the first broker to create /controller becomes the controller.
- Topic and partition metadata, dynamic configuration and quotas.
- ACLs when the ZooKeeper-based authoriser is in use, and often SCRAM credentials.
Which ZooKeeper version ships with Apache Kafka
From gradle/dependencies.gradle at each release tag. The Kafka distribution ships the ZooKeeper jar and the zookeeper-server-start.sh script, so many teams run the bundled version as their ensemble.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| Kafka 2.8.2 | 3.5.9 | End of life since 1 June 2022Bundles log4j 1.2.17 | 1 (CVE-2023-44981)2026 advisories not assessed for this line |
| Kafka 3.0.2 to 3.3.2 | 3.6.3 | End of life since 30 December 2022Bundles log4j 1.2.17 | 2 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line |
| Kafka 3.4.1 and 3.5.2 | 3.6.4 | End of life since 30 December 2022 | 2 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line |
| Kafka 3.6.2, 3.7.2 and 3.9.2 | 3.8.4 | Supported (latest 3.8.7) | 5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.5.9 is exposed to
CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1
SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.
Find the mode and the bundled ZooKeeper
# ZooKeeper mode if server.properties sets zookeeper.connect grep -E '^(zookeeper.connect|process.roles)' config/server.properties # The ZooKeeper jar shipped with this Kafka build ls libs/ | grep -E '^zookeeper-[0-9]' # Version of the running ensemble echo srvr | nc zk1.internal 2181 | head -1
Can Apache Kafka run without ZooKeeper?
Yes, from 3.3 onwards in KRaft mode, and only in KRaft mode from 4.0. Moving an existing cluster is a supported migration (bridge release, dual-write, then controller cutover), but it has to happen on 3.x before the 4.0 upgrade. Kafka 3.9 and 4.0 now sit under the project's archived releases, so every ZooKeeper-mode cluster is outside community support.
Community-supported Kafka lines are 4.1, 4.2 and 4.3. 3.9.x and 4.0.x are archived.
Your options
Migrate to KRaft on 3.9
The supported path: run the ZooKeeper-to-KRaft migration on 3.9, then upgrade to 4.x. It also needs a client inventory, because 4.0 drops very old client protocol versions.
Stay on ZooKeeper mode, patched
When the migration is scheduled for next year, OSSeva patches the Kafka 3.x broker and the ZooKeeper ensemble under it, so the cluster passes scans while the KRaft plan runs on your timeline.
Most teams buy this at the product level: keep the Apache Kafka estate supported, including the ZooKeeper under it. See Kafka on ZooKeeper extended support.
Frequently asked questions
Does Apache Kafka still use ZooKeeper?
Not from 4.0. Kafka 4.0, released on 18 March 2025, supports only KRaft mode. Kafka 3.x can still run on ZooKeeper, and 3.9 is the last line that can, but 3.9 is now listed as an archived release.
Why did Kafka remove ZooKeeper?
To run one system instead of two. KRaft keeps cluster metadata in an internal Raft-replicated log on the controllers, which removes the separate ensemble to deploy, secure and upgrade, and speeds up controller failover.
Which ZooKeeper version does Kafka 3.9 ship?
ZooKeeper 3.8.4, the same as Kafka 3.6 and 3.7. ZooKeeper 3.8.4 predates the fixes for CVE-2026-24281, CVE-2026-24308 and the September 2026 advisories, which arrived in 3.8.6 and 3.8.7.
Keep Apache Kafka and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.