// OSSeva Blog
OperationsWho Provides Support for Hazelcast IMDG 3.x, 4.x and Older 5.x Releases?
The short answer
For Hazelcast Platform 5.x Enterprise, Hazelcast itself supports each release through standard and extended support windows, with 24x7 support and hot fix patches. For Platform 5.1, 5.2 and 5.3, HeroDevs publishes Never-Ending Support builds that keep the same Maven coordinates. For IMDG 3.12, 4.0 and 4.2, and for Platform 5.3, OSSeva publishes patched builds, with client and member artifacts released together. Perforce OpenLogic sells Hazelcast technical support at all three of its support levels.
The question to settle first is which edition you run. Since Hazelcast Platform 5.4, patch releases go only to Enterprise customers, and the Community Edition gets security fixes only in new minor and major releases. A community cluster on an older release has no patch path from Hazelcast without an upgrade or a subscription.
Where Hazelcast versions stand
Hazelcast development runs on the Platform 5.x line, and the current release is 5.7.0, from 13 May 2026. IMDG 3.x and 4.x deployments sit outside it.
| Line | Status on 7 October 2026 | Patch releases |
|---|---|---|
| Platform 5.7 | Current | Enterprise only; Community gets fixes in the next minor release |
| Platform 5.4 to 5.6 | Superseded | Enterprise only, within Hazelcast's support windows |
| Platform 5.0 to 5.3 | Superseded | No longer released for Community; Enterprise within support windows |
| IMDG 4.x | Several majors behind | Community fixes ship only in new releases, so none reach 4.x |
| IMDG 3.12 | Several majors behind | Community fixes ship only in new releases, so none reach 3.12 |
Hazelcast publishes the exact standard and extended support dates for each release in its support portal. The Hazelcast end-of-life chart tracks them, and Hazelcast vulnerabilities by version lists the advisories that reach each line.
Hazelcast support providers compared
Each row reflects what the provider publishes on its own site as of 7 October 2026.
| Provider | What it covers | Hazelcast versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| Hazelcast | 24x7 support with a one-hour SLA, hot fix patches and CVE patch releases for Enterprise customers, with standard and extended support options | Platform 5.x releases within their support windows | Enterprise subscription | Yes, on Enterprise Edition |
| HeroDevs (NES for Hazelcast) | CVE fixes for Hazelcast core and hazelcast-spring, plus bundled dependencies such as Jackson-core, with VEX statements and SLA-backed delivery | 5.1.x, 5.2.x and 5.3.x | Drop-in Maven artifacts with the same coordinates | Yes |
| Perforce OpenLogic | Hazelcast technical support at Gold, Silver and Bronze levels | No version list published | Support subscription | Yes |
| OSSeva | Security backports with deserialization and cluster protocol advisories prioritised, member and client artifacts released together; grid audit on Assure; 24/7 operations on Operate | IMDG 3.12, 4.0 and 4.2, and Platform 5.3 | Signed Maven and Docker artifacts | Yes |
HeroDevs and OSSeva overlap on Platform 5.3 only. HeroDevs covers the earlier 5.x releases, and OSSeva covers the IMDG 3.x and 4.x lines that came before Platform.
How the providers differ
Hazelcast
For a cluster on Enterprise Edition, or one that can move to it, Hazelcast is the direct answer: patch releases and CVE fixes as soon as they are ready, 24x7 support with a one-hour SLA, and hot fix patches. Its documentation includes upgrade guides from IMDG 4.x and 3.12.x and a Data Migration Tool for moving 3.12 data. The Operator and the CP Subsystem left the Community Edition at 5.5 and remain in Enterprise. The IMDG 3 to 5 migration guide covers that path.
HeroDevs
HeroDevs' Never-Ending Support for Hazelcast covers Platform 5.1, 5.2 and 5.3 with builds that keep the same groupId and artifactId, so only the version string changes. It patches Hazelcast core and the hazelcast-spring integration, includes fixes for bundled dependencies, and ships VEX statements with each release. It suits teams on an early Platform 5.x release that want a drop-in fix. See OSSeva vs HeroDevs.
Perforce OpenLogic
OpenLogic lists Hazelcast at all three of its support levels, which suits teams that want help running and upgrading Hazelcast inside a wider contract. It does not publish patched Hazelcast builds. See OSSeva vs OpenLogic.
OSSeva
OSSeva for Hazelcast patches the line already in production, so the serialization format, cluster protocol and client compatibility your applications depend on stay fixed. Patch delivers security backports for IMDG 3.12, 4.0 and 4.2 and Platform 5.3, with deserialization and cluster protocol advisories prioritised and member and client artifacts built and released together, as signed Maven and Docker artifacts. Assure adds a topology, partition and split-brain review, a member port and join-mechanism audit, a serialization and class filtering review and an assessment of upgrade or migration options. Operate adds 24/7 heap, partition and member monitoring, a 15-minute P1 response, a named data grid engineer and executed rolling upgrades or migrations, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. Pricing is per cluster, not per member, gigabyte or client connection.
How to choose
| Situation | Usual answer |
|---|---|
| On Enterprise Edition, or ready to buy it | Hazelcast, on a release within its support windows |
| Community Edition and able to upgrade each minor release | Stay on the newest minor, which carries the latest fixes |
| Community Edition on Platform 5.1 to 5.3 | HeroDevs NES, or OSSeva for 5.3, while the upgrade is planned |
| IMDG 3.12 or 4.x that cannot move yet | OSSeva patched builds while the migration to 5.x is planned |
| Need help running the grid more than patches | Hazelcast Enterprise support, OpenLogic, or OSSeva Operate |
Hazelcast IMDG extended support covers the 3.x and 4.x case in more detail.
Where OSSeva fits
OSSeva covers the IMDG 3.x and 4.x lines that predate Hazelcast Platform, and Platform 5.3, which suits grids whose applications depend on the old serialization format and client protocol. OSSeva also covers GemFire and Ignite, so a comparison of grids is not a sales exercise for one of them.
Frequently asked questions
Who provides extended support for Hazelcast IMDG 3.12 and 4.x?
OSSeva publishes patched builds of IMDG 3.12, 4.0 and 4.2. OpenLogic sells Hazelcast technical support. HeroDevs' Hazelcast coverage starts at Platform 5.1.
Does Hazelcast Community Edition still get security patches?
Only in new minor and major releases. Since Platform 5.4, patch releases such as 5.4.1 or 5.5.2 are available only to Enterprise customers, and Community Edition CVE fixes arrive in the next minor release. The Community Edition remains under the Apache 2.0 licence.
Which companies offer Hazelcast support besides Hazelcast?
HeroDevs, for patched Platform 5.1 to 5.3 builds. Perforce OpenLogic, for technical support. OSSeva, for patched IMDG 3.12, 4.x and Platform 5.3 builds with optional 24/7 operations.
Can I patch Hazelcast 5.3 without upgrading?
Yes. HeroDevs and OSSeva both publish patched 5.3 builds, and Hazelcast Enterprise customers get 5.3 fixes for as long as 5.3 is inside Hazelcast's support windows.
Is it hard to upgrade from IMDG 3.12 to Platform 5?
It is a migration rather than a rolling upgrade. Hazelcast documents separate upgrade paths from IMDG 4.x and 3.12.x and provides a Data Migration Tool for moving 3.12 data, and client compatibility has to be checked across the jump.
Tags
Related articles
How to Document End-of-Life Software Risk: Risk Register, Exceptions and Compensating Controls
October 7, 2026ComplianceEnd-of-Life Software Policy Template for Open Source Infrastructure
October 7, 2026OperationsWho Provides Support for Apache Hadoop 2.x and 3.x After End of Life?
October 7, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.