// OSSeva Blog
OperationsWho Provides Extended Support for Apache Pulsar 3.0 LTS and 4.0?
The short answer
For Pulsar 3.0 LTS, whose security support ended on 2 May 2026, OSSeva publishes patched builds for 3.0, 3.1 and 3.2, along with 2.10, 2.11 and 4.0. IBM Elite Support for Apache Pulsar, formerly DataStax Luna Streaming, ships its own Pulsar 3.1 distribution with support. StreamNative runs Pulsar as a cloud service or on your own Kubernetes through StreamNative Private Cloud, and Perforce OpenLogic sells Pulsar support contracts.
For Pulsar 4.0 LTS, Apache still ships security fixes until 21 October 2027, but bug fixes stop on 21 October 2026. The supported path from there is 5.0 LTS, released on 5 October 2026.
Which Pulsar versions Apache still supports
Pulsar's release policy gives each LTS 24 months of active support and 36 months of security support, and each feature release six months. It also says the project does not announce end-of-support dates separately, so the table on that page is the notice.
| Line | Active support | Security support | Latest release |
|---|---|---|---|
| 5.0 LTS | To 5 October 2028 | To 5 October 2029 | 5.0.0 (5 October 2026) |
| 4.2 | Ended 24 September 2026 | Ended 24 September 2026 | 4.2.5 |
| 4.1 | Ended 8 March 2026 | Ended 8 March 2026 | 4.1.3 |
| 4.0 LTS | Ends 21 October 2026 | To 21 October 2027 | 4.0.14 (5 October 2026) |
| 3.1 to 3.3 | Ended | Ended between February and December 2024 | 3.1.3, 3.2.4, 3.3.9 |
| 3.0 LTS | Ended 2 May 2025 | Ended 2 May 2026 | 3.0.17 |
| 2.10 and 2.11 | Ended | Ended in 2023 and January 2024 | 2.10.6, 2.11.4 |
Past those dates, the project may make ad hoc releases on a "best-effort" basis, and its policy notes that commercial vendors may offer paid support for earlier versions. Live upgrade and downgrade work between consecutive LTS releases, so a 3.0 cluster goes to 4.0 before 5.0. The Pulsar end-of-life chart tracks every line, and Pulsar vulnerabilities by version lists the advisories.
Apache Pulsar support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | Pulsar versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| StreamNative | StreamNative's data streaming platform running Pulsar and Kafka, as a cloud service or self-managed on Kubernetes with operators and an uptime SLA for enterprise deployments | No support policy for community Pulsar versions published | StreamNative Cloud (Serverless, Dedicated, BYOC) or StreamNative Private Cloud | Yes, through Private Cloud on Kubernetes |
| IBM Elite Support for Apache Pulsar (formerly DataStax Luna Streaming) | A supported Pulsar distribution with a Helm chart for any CNCF-conformant Kubernetes, connectors, Starlight protocol handlers for Kafka, RabbitMQ and JMS, and an admin console | Pulsar 3.1 distribution; the previous release was 2.10.x | IBM support offering; IBM also runs Astra Streaming as a managed service | Yes, on Kubernetes |
| Perforce OpenLogic | Technical support for Pulsar at Gold, Silver and Bronze levels; Pulsar is not on its patched long-term support list | No version list published | Support subscription | Yes |
| OSSeva | Backported CVE fixes for brokers, BookKeeper and the ZooKeeper metadata store; multi-tenant security audit and Oxia migration planning on Assure; 24/7 operations with Functions and IO connector coverage on Operate | 2.10, 2.11, 3.0, 3.1, 3.2 and 4.0; 5.0 also listed | Signed Docker images and Helm charts | Yes |
One row needs a note. IBM's distribution follows its own version numbers, and its latest release is Pulsar 3.1, a line Apache stopped supporting in February 2024. Ask IBM how long that release is supported and how fixes reach it before planning around it.
How the providers differ
StreamNative
StreamNative is the strongest choice when you want a commercial platform built around Pulsar and are willing to adopt it: managed clusters in its cloud or yours, or StreamNative Private Cloud with Kubernetes operators on your own infrastructure. Its Private Cloud operator is actively released, with v0.20.14 on 29 September 2026. It does not publish which community Pulsar versions it supports outside its platform, so a team that wants to keep running its own Pulsar build unchanged should ask that question directly.
IBM (formerly DataStax)
After IBM acquired DataStax, Luna Streaming became IBM Elite Support for Apache Pulsar, with the same documentation. It packages Pulsar 3.1 with connectors, the Starlight protocol handlers and an admin console, and runs on any CNCF-conformant Kubernetes. Astra Streaming continues as IBM's hosted Pulsar service. Teams already on Luna Streaming have a continuing vendor, though on a 3.1 base.
Perforce OpenLogic
OpenLogic lists Pulsar at all three of its support levels, as part of a catalogue of more than 400 technologies. It helps run Pulsar but does not publish patched builds for end-of-life lines. See OSSeva vs OpenLogic.
OSSeva
OSSeva for Apache Pulsar patches the community Pulsar you already run, on your infrastructure, across 2.10 to 4.0. Coverage includes the ZooKeeper metadata store that 2.x and early 3.x depend on, and ZooKeeper-mode deployments on every patched line plus Oxia-mode on 4.0. Assure adds a namespace isolation audit, JWT and TLS configuration review, geo-replication review and ZooKeeper to Oxia migration planning. Operate adds 24/7 broker, bookie and ZooKeeper monitoring, backlog alerting, a 15-minute P1 response and coverage for Pulsar Functions and IO connectors. Pricing is per cluster, not per topic or message.
How to choose
| Situation | Usual answer |
|---|---|
| On 4.0 LTS | Upstream security fixes continue to 21 October 2027; plan the move to 5.0 LTS, which requires Java 21 on servers |
| On 3.0 LTS, able to take a rolling upgrade this quarter | Upgrade to 4.0, then 5.0 |
| On 3.0 to 3.2, or 2.10 and 2.11, with no upgrade window yet | OSSeva patched builds while the upgrade is planned |
| Want a vendor platform and managed operations around Pulsar | StreamNative Cloud or Private Cloud |
| Already on Luna Streaming | IBM Elite Support for Apache Pulsar, after confirming its support dates for 3.1 |
Our Pulsar 3.0 to 4.0 upgrade guide covers the rolling upgrade across brokers, BookKeeper and the metadata store, and Pulsar production support covers running it with OSSeva.
Where OSSeva fits
OSSeva keeps community Pulsar patched on the line you run, from 2.10 to 4.0, without moving to a vendor platform, and can operate the clusters 24/7. See the extended support vendor roundup for how OSSeva compares across other technologies.
Frequently asked questions
Who provides extended support for Apache Pulsar 3.0 LTS?
OSSeva publishes patched builds for Pulsar 3.0, along with 2.10 to 3.2 and 4.0. IBM Elite Support for Apache Pulsar, formerly Luna Streaming, supports its own Pulsar 3.1 distribution. StreamNative and OpenLogic support Pulsar more broadly but publish no extended support for 3.0.
When does Pulsar 4.0 LTS reach end of life?
Active support ends on 21 October 2026 and security support on 21 October 2027, according to Pulsar's release policy. After 21 October 2026, 5.0 is the only line with active support.
What happened to DataStax Luna Streaming?
IBM acquired DataStax, and Luna Streaming is now IBM Elite Support for Apache Pulsar. The documentation says the two names refer to the same product, and its latest release distributes Pulsar 3.1.
Can we upgrade straight from Pulsar 3.0 to 5.0?
No. The release policy supports live upgrade and downgrade between one LTS and the next, so 3.0 moves to 4.0 first. It lists 3.2 to 5.0 as not supported.
Is Pulsar 3.0 still getting security fixes?
Not on a schedule. Security support ended on 2 May 2026, and 3.0.17 was the last release. Apache may make ad hoc releases on a best-effort basis, and otherwise fixes come from a commercial vendor.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.