// What runs on ZooKeeper / solr

Does Apache Solr use ZooKeeper?

Required for SolrCloud

Yes. SolrCloud keeps its cluster state, collection configuration and leader information in ZooKeeper, and that is still true in Solr 10, released in March 2026. Solr can start an embedded ZooKeeper, but the reference guide says to use an external ensemble in production because the embedded one provides no failover.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Solr uses ZooKeeper for

  • Cluster state: live nodes, collections, shards and replicas.
  • Configsets: solrconfig.xml and schema files are uploaded to and read from ZooKeeper.
  • Shard leader election and overseer election.
  • Security configuration (security.json) for the cluster.

Which ZooKeeper version ships with Apache Solr

From the dependency version files at each release tag. Solr 10 routes all ZooKeeper access through Apache Curator.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Solr 8.0.03.4.13End of life since 1 June 2020Bundles log4j 1.2.172 (CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
Solr 8.11.4 (last Solr 8)3.6.2End of life since 30 December 2022Bundles log4j 1.2.172 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line
Solr 9.0.03.7.0End of life since 2 February 2024Bundles log4j 1.2.172 (CVE-2023-44981, CVE-2024-23944)2026 advisories not assessed for this line
Solr 9.10.1 (last Solr 9)3.9.4Supported (latest 3.9.6)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Solr 10.0.03.9.4Supported (latest 3.9.6)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.4.13 is exposed to

CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5

getACL() performs no permission check and exposes unsalted digest authentication hashes.

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

Find the ZooKeeper Solr is using

# ZooKeeper client jar in the Solr install
ls server/solr-webapp/webapp/WEB-INF/lib/ | grep -E '^zookeeper-[0-9]'

# The ensemble Solr points at
grep -E '^ZK_HOST' bin/solr.in.sh

echo srvr | nc zk1.internal 2181 | head -1

Can Apache Solr run without ZooKeeper?

Not in SolrCloud mode. Standalone (user-managed) Solr runs without ZooKeeper but gives up distributed indexing and automatic failover. There is no plan in Solr's issue tracker to remove ZooKeeper.

Solr 8 reached end of life on 25 October 2024. Solr 9.10.1 is the last 9.x release, and every version below 9.10 is end of life. Solr 10 is the current stable line.

Your options

Upgrade Solr

Solr 8 to 9 or 10 is a real migration, with reindexing where schemas change. It also moves you to a supported ZooKeeper client.

Keep Solr 8, patched

OSSeva patches Solr 7 and 8 and the ZooKeeper ensemble behind them, so a search cluster that cannot be reindexed this quarter stays within audit.

Most teams buy this at the product level: keep the Apache Solr estate supported, including the ZooKeeper under it. See Apache Solr extended support.

Frequently asked questions

Does Solr need ZooKeeper?

SolrCloud does, in every version including Solr 10. Only standalone, non-cloud Solr runs without it.

Can I use the embedded ZooKeeper that ships with Solr?

For development. The Solr reference guide recommends an external ensemble in production, because the embedded ZooKeeper does not provide failover.

Which ZooKeeper does Solr 8.11 use?

Solr 8.11.4 bundles ZooKeeper 3.6.2. The 3.6 line reached end of life on 30 December 2022 and has no fix for CVE-2023-44981 or CVE-2024-23944.

Keep Apache Solr and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.