// What runs on ZooKeeper / storm

Does Apache Storm use ZooKeeper?

Required

Yes. The Storm cluster setup guide makes a ZooKeeper cluster step one: Nimbus and the supervisors coordinate through it, and storm.zookeeper.servers is mandatory configuration. That is still true of Storm 3.1.0, released in September 2026.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Storm uses ZooKeeper for

  • Cluster coordination between Nimbus and the supervisors.
  • Heartbeats and topology assignment state.

Which ZooKeeper version ships with Apache Storm

From the zookeeper.version property in pom.xml at each release tag.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Storm 2.4.03.5.9End of life since 1 June 2022Bundles log4j 1.2.171 (CVE-2023-44981)2026 advisories not assessed for this line
Storm 2.8.9 (last 2.x)3.9.5Supported (latest 3.9.6)3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
Storm 3.1.03.9.5Supported (latest 3.9.6)3 (CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.5.9 is exposed to

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

Find the ZooKeeper Storm is using

grep -A3 storm.zookeeper.servers conf/storm.yaml

ls lib/ | grep -E '^zookeeper-[0-9]'

Can Apache Storm run without ZooKeeper?

No. Every Storm release requires ZooKeeper.

Storm 2.8.9 (22 July 2026) is the final 2.x release. Storm 3.x requires Java 25.

Your options

Upgrade to Storm 3

The move to Java 25 is the hard part for older topologies.

Patch Storm 2.x and its ZooKeeper

OSSeva ships patched Storm 2.x builds and patches the ZooKeeper ensemble under them.

Most teams buy this at the product level: keep the Apache Storm estate supported, including the ZooKeeper under it. See Apache Storm extended support.

Frequently asked questions

Is Storm 2.x end of life?

Yes. Storm 2.8.9, released on 22 July 2026, is the final 2.x release, and the branch is no longer maintained.

Keep Apache Storm and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.