// What runs on ZooKeeper / pulsar

Does Apache Pulsar and BookKeeper use ZooKeeper?

Default; Oxia available

Yes. Pulsar keeps its metadata and configuration stores in ZooKeeper by default, and BookKeeper, Pulsar's storage layer, documents a ZooKeeper cluster as a deployment requirement. Oxia has been an alternative metadata store since Pulsar 3.3.0, and the Pulsar 5.0 preview makes Oxia the recommended store and adds live migration from ZooKeeper.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Pulsar and BookKeeper uses ZooKeeper for

  • Local metadata store: topic ownership, namespace bundles and broker load data.
  • Configuration store: tenants, namespaces and policies across clusters.
  • BookKeeper ledger metadata and bookie registration.

Which ZooKeeper version ships with Apache Pulsar and BookKeeper

From the zookeeper.version property in pom.xml at each release tag.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Pulsar 2.10.63.9.1Supported (latest 3.9.6)8 (CVE-2024-23944, CVE-2024-51504, CVE-2025-58457, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Pulsar 3.0.143.9.3Supported (latest 3.9.6)6 (CVE-2025-58457, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Pulsar 4.0.93.9.4Supported (latest 3.9.6)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.9.1 is exposed to

CVE-2024-23944 · CVSS 5.3 · fixed in 3.8.4, 3.9.2

Persistent watchers skip the ACL check on child znodes, leaking their paths.

CVE-2024-51504 · CVSS 9.1 · fixed in 3.9.3

AdminServer IP authentication trusts X-Forwarded-For, allowing an authentication bypass.

CVE-2025-58457 · CVSS 4.3 · fixed in 3.9.4

AdminServer snapshot and restore commands run with insufficient permission checks.

CVE-2026-24281 · CVSS 7.4 · fixed in 3.8.6, 3.9.5

TLS hostname verification falls back to reverse DNS, allowing server or client impersonation.

CVE-2026-24308 · CVSS 7.5 · fixed in 3.8.6, 3.9.5

Sensitive client configuration values are written to the log at INFO level.

CVE-2026-59739 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944.

CVE-2026-59969 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum.

CVE-2026-79993 · CVSS 7.5 · fixed in 3.8.7, 3.9.6

The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes.

Find the metadata store Pulsar is using

grep -E '^(metadataStoreUrl|configurationMetadataStoreUrl)' conf/broker.conf

ls lib/ | grep -E 'zookeeper-[0-9]'

Can Apache Pulsar and BookKeeper run without ZooKeeper?

Yes, with Oxia from Pulsar 3.3.0 onwards. Pulsar 5.0 (in preview) adds zero-downtime migration from ZooKeeper to Oxia and removes the etcd metadata store.

Pulsar 3.0 LTS security support ended on 2 May 2026.

Your options

Upgrade Pulsar

Recent Pulsar lines bundle current 3.9 ZooKeeper releases, and 5.0 adds a live path to Oxia.

Keep Pulsar 3.0, patched

OSSeva patches Pulsar 3.0 and the ZooKeeper and BookKeeper layers under it.

Most teams buy this at the product level: keep the Apache Pulsar and BookKeeper estate supported, including the ZooKeeper under it. See Apache Pulsar extended support.

Frequently asked questions

Does Pulsar still need ZooKeeper?

By default, yes. From 3.3.0 you can use Oxia instead, and Pulsar 5.0 recommends Oxia and adds a live migration path. ZooKeeper remains fully supported.

Keep Apache Pulsar and BookKeeper and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.