// OSSeva Blog
OperationsWho Provides Extended Support for Apache Camel 3 and Camel 4 LTS?
The short answer
For Camel 3, which Apache stopped releasing at the end of 2024, OSSeva publishes patched builds of the 3.14 and 3.20 LTS lines, along with Camel 2.25 and the expired 4.4 and 4.8 LTS lines. Red Hat no longer supports Camel 3: its Camel for Spring Boot 3.20 product ended on 30 September 2024. For Camel 4, Red Hat supports its own build of Apache Camel 4 until 30 October 2029, while Perforce OpenLogic and meshIQ sell support contracts for community Camel.
The difference that matters is whether a provider ships new security fixes for the exact line you run, or helps you run it and upgrade. Red Hat ships fixes for its latest Camel 4 release only. OSSeva ships them for lines Apache has retired.
Which Camel versions Apache still supports
Camel's download page says LTS releases get bug and security fixes "for a longer time - up to one year", and it lists only the supported releases. Everything else sits in the release archive.
| Line | Status on 6 October 2026 | Latest release | End of life |
|---|---|---|---|
| Camel 4.22 LTS | Supported | 4.22.1 (September 2026) | August 2027 |
| Camel 4.18 LTS | Supported | 4.18.4 (August 2026) | February 2027 |
| Camel 4.4, 4.8 and other earlier 4.x LTS lines | Archived | No further releases | Passed |
| Camel 3.x, including 3.14, 3.20 and 3.22 LTS | End of life | 3.22.4 (March 2025) | End of 2024, announced 23 December 2024 |
| Camel 2.x | End of life | No further releases | Passed |
Two supported lines at a time, each for about a year, means a Camel estate falls out of support within twelve months of its last upgrade. The Camel end-of-life chart tracks every line, and Camel vulnerabilities by version shows which advisories reach the retired ones.
Apache Camel support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | Camel versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| Red Hat build of Apache Camel | Red Hat's own Camel 4 product for Spring Boot and Quarkus, with security and bug fixes on its latest release; optional Extended Life Cycle Support add-on | Camel 4.x product: full support to 30 October 2028, maintenance to 30 October 2029, ELS to 29 October 2030. Camel 3 products ended by 30 September 2024 | Red Hat subscription (Red Hat Application Foundations or Red Hat build of Apache Camel) | Yes, on supported configurations |
| Red Hat Fuse 7 | Red Hat's earlier integration product, built on Camel 2.x | Maintenance ended 30 June 2024; paid ELS phases run to 30 June 2027 | Red Hat subscription with ELS add-on | Yes |
| Perforce OpenLogic | Technical support for community Camel at Gold, Silver and Bronze levels, plus Apache Camel training; Camel is not on its patched long-term support list | No version list published | Support subscription | Yes |
| meshIQ | Enterprise support and services for Apache Camel alongside ActiveMQ and Artemis | Camel 4.x | Support subscription and services | Yes |
| OSSeva | Backported CVE fixes for the Camel components you use and the libraries they bundle, with priority for marshalling and expression-language advisories; route inventory and migration planning on higher tiers | 2.25, 3.14 LTS, 3.20 LTS, 4.4 LTS and 4.8 LTS now; 4.18 LTS after February 2027 | Signed Maven artifacts through a BOM, for Maven, Gradle and Spring Boot starters | Yes |
One row needs reading closely. Red Hat's policy is that defect and security fixes go only to the latest minor or micro release, so a Red Hat subscription keeps you current on Red Hat's Camel 4 stream rather than keeping an older line alive. HeroDevs is not in the table: its current support catalogue lists no Camel product.
How the providers differ
Red Hat
Red Hat is the strongest choice for Camel 4 when you can follow its release stream. Its build of Apache Camel 4 now has one life cycle across Spring Boot and Quarkus, with full support until 30 October 2028. Red Hat aims for a new minor about every six months, usually aligned to an upstream LTS: the Spring Boot variant shipped 4.18.4 on 24 September 2026, and the Quarkus variant ships on Camel 4.18.3. That window is far longer than Apache's one year, as long as you keep moving to Red Hat's latest release. Red Hat's Camel 3 products, Camel for Spring Boot 3.14 to 3.20 and Camel K 1.x, have all ended, and Fuse 7 on Camel 2 is in paid extended life phases until June 2027.
Perforce OpenLogic
OpenLogic lists Apache Camel among more than 400 supported technologies at all three support levels and runs a Camel training course. Its long-term support product, which supplies patched builds after end of life, does not include Camel. Our OSSeva vs OpenLogic comparison covers the wider overlap.
meshIQ
meshIQ sells Camel 4.x support together with ActiveMQ and Artemis, which suits estates where the routes and the brokers are one system. It does not publish Camel 2 or 3 coverage.
OSSeva
OSSeva for Apache Camel backports security fixes onto the LTS line your routes were written against, so a Camel 3 estate is not forced into the javax to jakarta rewrite by a security deadline. Patching covers the components in use, including the third-party libraries they bundle, and the swap is a BOM change with component coordinates unchanged. Camel Spring Boot pins a Spring Boot line, and OSSeva covers both sides under the same engagement. Assure adds a route and component inventory, a Jakarta migration impact assessment and a staged upgrade plan; Operate adds 24/7 route monitoring, a 15-minute P1 response and migration execution. Pricing is per application estate, not per route.
How to choose
| Situation | Usual answer |
|---|---|
| On Camel 4.18 or 4.22 and able to upgrade once or twice a year | Stay on upstream LTS, or Red Hat's build if you want a vendor behind it |
| On Camel 4 and wanting a multi-year window from the project's main commercial backer | Red Hat build of Apache Camel, on its latest release |
| On Camel 3.x with hundreds of routes and no Jakarta budget this year | Patched 3.14 or 3.20 builds from OSSeva while the migration is planned |
| On an expired 4.x LTS such as 4.4 or 4.8 | A minor move to 4.18 or 4.22 if possible; OSSeva builds if the regression cycle is the blocker |
| On Fuse 7 | Red Hat ELS to June 2027 if you hold it, then a move to Camel 4 |
Camel 3 to 4 changes every javax import and raises the Java baseline to 17. Our Camel 3 to 4 migration guide covers the steps, and Camel 3 Jakarta migration covers running the move alongside extended support.
Where OSSeva fits
OSSeva covers the Camel lines Apache has retired, 2.25, 3.14, 3.20, 4.4 and 4.8, and will cover 4.18 when it leaves upstream support, with signed artifacts through your repository manager. It can also cover the Spring Boot and ActiveMQ releases those routes depend on. See the extended support vendor roundup for how OSSeva compares across other technologies.
Frequently asked questions
Who provides extended support for Apache Camel 3?
OSSeva publishes patched builds for the Camel 3.14 and 3.20 LTS lines. Apache ended Camel 3 at the end of 2024, and Red Hat's Camel 3 products have also ended, the last on 30 September 2024. OpenLogic sells general Camel support, but Camel is not on its patched long-term support list.
Who supports Camel 4 LTS for longer than a year?
Red Hat, for its own build of Apache Camel 4, with full support to 30 October 2028 and maintenance to 30 October 2029, provided you stay on its latest release. OSSeva patches Camel 4 LTS lines after Apache retires them, today 4.4 and 4.8, and 4.18 from February 2027.
Is Camel 3 still supported?
Not by Apache. The Camel team declared Camel 3 end of life at the end of 2024, and 3.22.4 in March 2025 was the last release. Only Camel 4.22 and 4.18 LTS are supported upstream.
Does Red Hat still support Camel 3 or Fuse?
Not Camel 3: Red Hat's Camel for Spring Boot 3.20 ended on 30 September 2024 and Camel K 1.10 on 30 June 2025. Fuse 7 left maintenance on 30 June 2024, and its paid extended life phases run to 30 June 2027.
Does HeroDevs cover Apache Camel?
Its current support catalogue does not list Camel. Ask HeroDevs directly if you were quoted Camel coverage before.
Should we upgrade to Camel 4 or buy extended support for Camel 3?
Upgrade the applications whose routes, Spring Boot version and tests can move to Jakarta now. Buy extended support for the rest, with a migration date recorded for each, so the security exposure does not set the migration schedule.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.