// What runs on ZooKeeper / pinot

Does Apache Pinot use ZooKeeper?

Required (through Helix)

Yes. Pinot uses Apache Helix for cluster management, and Helix uses ZooKeeper as its state store. Pinot's documentation calls ZooKeeper a first-class citizen of a Pinot cluster.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Pinot uses ZooKeeper for

  • Cluster state and ideal state for segments, through Helix.
  • Table configuration and schemas.

Which ZooKeeper version ships with Apache Pinot

From the zookeeper.version property in pom.xml at the release tag (Helix 1.3.2).

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Pinot 1.5.13.9.5Supported (latest 3.9.6)3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.9.5 is exposed to

CVE-2026-59739 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944.

CVE-2026-59969 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum.

CVE-2026-79993 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes.

Find the ZooKeeper Pinot is using

grep -iE 'zk|zookeeper' conf/pinot-controller.conf

Can Apache Pinot run without ZooKeeper?

No.

Pinot 1.5.1 is the latest release.

Your options

Keep the ensemble current

Pinot 1.5 builds against ZooKeeper 3.9.5, which predates the September 2026 fixes in 3.9.6.

Most teams buy this at the product level: keep the Apache Pinot estate supported, including the ZooKeeper under it. See Apache Pinot support.

Frequently asked questions

Does Pinot need ZooKeeper?

Yes, through Apache Helix, which stores Pinot's cluster state in ZooKeeper.

Keep Apache Pinot and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.