// What runs on ZooKeeper / nifi

Does Apache NiFi use ZooKeeper?

Default for clusters

A NiFi cluster elects its Cluster Coordinator and Primary Node through ZooKeeper, and NiFi can start an embedded ZooKeeper server so you do not run a separate ensemble. NiFi 2.x keeps ZooKeeper as the default but adds Kubernetes-based leader election and a ConfigMap state provider as alternatives.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache NiFi uses ZooKeeper for

  • Cluster Coordinator and Primary Node election.
  • Cluster-wide state for processors (the ZooKeeper state provider).

Which ZooKeeper version ships with Apache NiFi

From the zookeeper.version property in pom.xml at each release tag. Many NiFi 1.x clusters run the embedded ZooKeeper (nifi.state.management.embedded.zookeeper.start=true).

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
NiFi 1.19.13.8.0Supported (latest 3.8.7)7 (CVE-2023-44981, CVE-2024-23944, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
NiFi 1.28.13.9.3Supported (latest 3.9.6)6 (CVE-2025-58457, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.8.0 is exposed to

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

CVE-2024-23944 · CVSS 5.3 · fixed in 3.8.4, 3.9.2

Persistent watchers skip the ACL check on child znodes, leaking their paths.

CVE-2026-24281 · CVSS 7.4 · fixed in 3.8.6, 3.9.5

TLS hostname verification falls back to reverse DNS, allowing server or client impersonation.

CVE-2026-24308 · CVSS 7.5 · fixed in 3.8.6, 3.9.5

Sensitive client configuration values are written to the log at INFO level.

CVE-2026-59739 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944.

CVE-2026-59969 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum.

CVE-2026-79993 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes.

Find the ZooKeeper NiFi is using

grep -E 'nifi.(zookeeper.connect.string|state.management.embedded.zookeeper.start|cluster.leader.election.implementation)' conf/nifi.properties

Can Apache NiFi run without ZooKeeper?

In NiFi 2.x on Kubernetes, yes: set the leader election implementation to KubernetesLeaderElectionManager and use the ConfigMap cluster state provider (subject to the 1 MB ConfigMap limit). NiFi 1.x clusters need ZooKeeper.

NiFi 1.28 is the last 1.x minor release, with end of support on 8 December 2024. NiFi 2.12.0 is current.

Your options

Upgrade to NiFi 2

A significant migration for flows that rely on components removed in 2.0, but it opens up Kubernetes-native clustering.

Keep NiFi 1.x, patched

OSSeva patches NiFi 1.x and its ZooKeeper, so dataflows stranded by the 2.0 rewrite stay supported.

Most teams buy this at the product level: keep the Apache NiFi estate supported, including the ZooKeeper under it. See Apache NiFi extended support.

Frequently asked questions

Can I run a NiFi cluster without ZooKeeper?

In NiFi 2.x on Kubernetes, yes, using Kubernetes leader election and the ConfigMap state provider. NiFi 1.x clusters require ZooKeeper, either embedded or external.

Keep Apache NiFi and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.