// What runs on ZooKeeper / pulsar
Does Apache Pulsar and BookKeeper use ZooKeeper?
Default; Oxia availableYes. Pulsar keeps its metadata and configuration stores in ZooKeeper by default, and BookKeeper, Pulsar's storage layer, documents a ZooKeeper cluster as a deployment requirement. Oxia has been an alternative metadata store since Pulsar 3.3.0, and the Pulsar 5.0 preview makes Oxia the recommended store and adds live migration from ZooKeeper.
Trusted globally by enterprises




What Apache Pulsar and BookKeeper uses ZooKeeper for
- Local metadata store: topic ownership, namespace bundles and broker load data.
- Configuration store: tenants, namespaces and policies across clusters.
- BookKeeper ledger metadata and bookie registration.
Which ZooKeeper version ships with Apache Pulsar and BookKeeper
From the zookeeper.version property in pom.xml at each release tag.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| Pulsar 2.10.6 | 3.9.1 | Supported (latest 3.9.6) | 8 (CVE-2024-23944, CVE-2024-51504, CVE-2025-58457, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
| Pulsar 3.0.14 | 3.9.3 | Supported (latest 3.9.6) | 6 (CVE-2025-58457, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
| Pulsar 4.0.9 | 3.9.4 | Supported (latest 3.9.6) | 5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.9.1 is exposed to
CVE-2024-23944 · CVSS 5.3 · fixed in 3.8.4, 3.9.2
Persistent watchers skip the ACL check on child znodes, leaking their paths.
CVE-2024-51504 · CVSS 9.1 · fixed in 3.9.3
AdminServer IP authentication trusts X-Forwarded-For, allowing an authentication bypass.
CVE-2025-58457 · CVSS 4.3 · fixed in 3.9.4
AdminServer snapshot and restore commands run with insufficient permission checks.
CVE-2026-24281 · CVSS 7.4 · fixed in 3.8.6, 3.9.5
TLS hostname verification falls back to reverse DNS, allowing server or client impersonation.
CVE-2026-24308 · CVSS 7.5 · fixed in 3.8.6, 3.9.5
Sensitive client configuration values are written to the log at INFO level.
CVE-2026-59739 · CVSS 7.5 · fixed in 3.8.7, 3.9.6
Reconnect watch replay skips the ACL check and leaks restricted paths; an incomplete fix of CVE-2024-23944.
CVE-2026-59969 · CVSS 7.5 · fixed in 3.8.7, 3.9.6
Quorum TLS in FIPS mode does not verify peer hostnames, so a CA-trusted certificate for another host can join the quorum.
CVE-2026-79993 · CVSS 7.5 · fixed in 3.8.7, 3.9.6
The deleteContainer request skips session and ACL checks, so an unauthenticated client can delete empty persistent, container or TTL znodes.
Find the metadata store Pulsar is using
grep -E '^(metadataStoreUrl|configurationMetadataStoreUrl)' conf/broker.conf ls lib/ | grep -E 'zookeeper-[0-9]'
Can Apache Pulsar and BookKeeper run without ZooKeeper?
Yes, with Oxia from Pulsar 3.3.0 onwards. Pulsar 5.0 (in preview) adds zero-downtime migration from ZooKeeper to Oxia and removes the etcd metadata store.
Pulsar 3.0 LTS security support ended on 2 May 2026.
Your options
Upgrade Pulsar
Recent Pulsar lines bundle current 3.9 ZooKeeper releases, and 5.0 adds a live path to Oxia.
Keep Pulsar 3.0, patched
OSSeva patches Pulsar 3.0 and the ZooKeeper and BookKeeper layers under it.
Most teams buy this at the product level: keep the Apache Pulsar and BookKeeper estate supported, including the ZooKeeper under it. See Apache Pulsar extended support.
Frequently asked questions
Does Pulsar still need ZooKeeper?
By default, yes. From 3.3.0 you can use Oxia instead, and Pulsar 5.0 recommends Oxia and adds a live migration path. ZooKeeper remains fully supported.
Keep Apache Pulsar and BookKeeper and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.