// OSSeva Blog
OperationsWho Provides RabbitMQ Support for 3.x and 4.x After Broadcom?
The short answer
For RabbitMQ 3.13 and 4.x with patches from the team that writes RabbitMQ, Broadcom sells commercial support, with indicative end dates of 31 December 2029 for 3.13 and 30 June 2030 for 4.2. For self-managed clusters without a Broadcom licence, OSSeva publishes patched builds of RabbitMQ 3.8 to 4.3, along with the Erlang/OTP release each one runs on. If you would rather not run brokers at all, Amazon MQ and CloudAMQP run 3.13 and 4.x as managed services, and Seventh State (part of Erlang Solutions) and Perforce OpenLogic sell RabbitMQ support and consulting without patched builds.
The question to settle first is where the next security fix comes from. In the community edition, only the newest minor gets public patch releases, so any older line now relies on a commercial release, a managed service or a patched build.
Which RabbitMQ versions are still supported
RabbitMQ's release information page lists two dates per line: the end of community support and an indicative end of commercial support. It says long-term support is available to users who hold a valid commercial support licence, and points to the Broadcom support portal for the official dates.
| Line | Community support | Commercial support (indicative) | Latest public release |
|---|---|---|---|
| 4.3 | To 30 November 2026 | To 30 April 2028 | 4.3.6 (16 September 2026) |
| 4.2 | Ended 31 July 2026 | To 30 June 2030 | 4.2.10 (17 August 2026) |
| 4.1 | Ended 31 January 2026 | To 30 April 2027 | 4.1.8 |
| 4.0 | Ended 30 April 2025 | Ended 30 September 2026 | 4.0.9 |
| 3.13 | Ended 30 September 2024 | To 31 December 2029 | 3.13.7 |
| 3.12 | Ended 29 February 2024 | Ended 30 June 2025 | 3.12.14 |
| 3.11 and 3.10 | Ended 2023 and 2022 | Ended 30 June 2024 and 31 December 2023 | 3.11.28, 3.10.25 |
Two things stand out. Broadcom's commercial window for 3.13 runs years past its community date, so 3.13 is commercially alive while community 3.13.7 is frozen. And 4.0's commercial support ended a week ago, so a 4.0 cluster now has no vendor patch stream from the project at all. The RabbitMQ end-of-life chart tracks every line, and RabbitMQ vulnerabilities by version shows which advisories reach each one.
RabbitMQ support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | RabbitMQ versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| Broadcom (VMware Tanzu RabbitMQ) | Commercial support and commercial patch releases from the team that develops RabbitMQ | 3.13 to 31 December 2029; 4.1, 4.2 and 4.3 to 2027, 2030 and 2028 (indicative) | Broadcom commercial licence | Yes |
| Amazon MQ for RabbitMQ | Managed brokers; AWS upgrades brokers automatically within 45 days of a version's end of support on the service | 4.3 and 4.2 (mq.m7g only) and 3.13; 3.12 ended on 17 March 2025; no end date published yet for 3.13 | AWS managed service | No |
| CloudAMQP | Hosted RabbitMQ clusters; old versions upgraded through scheduled maintenance | 3.13.x is the minimum for new clusters, and versions before 3.13 are being phased out | Managed service | No |
| Seventh State (Erlang Solutions) | RabbitMQ consultancy, health checks, 24/7 support plans, disaster recovery, troubleshooting and training | No version list published | Support plans and services | Yes |
| Perforce OpenLogic | Technical support for RabbitMQ at Gold, Silver and Bronze levels; RabbitMQ is not on its patched long-term support list | No version list published | Support subscription | Yes |
| OSSeva | Backported CVE fixes on community RabbitMQ source, with a validated Erlang/OTP build for each release; architecture audits and attestation packs on Assure; 24/7 operations on Operate | 3.8 to 3.13, 4.0, 4.1 and 4.2, and 4.3 after 30 November 2026 | Signed Helm, OCI and Maven artifacts | Yes |
Two rows need care. Amazon MQ and CloudAMQP keep you on a supported version by upgrading the broker, so they are a route off old lines rather than a way to stay on one. And Seventh State and OpenLogic help you run RabbitMQ, but neither publishes patched builds for lines the community has retired.
How the providers differ
Broadcom
Broadcom develops RabbitMQ, and the project's release page says long-term support beyond the community dates goes to holders of a commercial licence. If you want patches from the people who write the broker, and the licensing fits your estate, it is the most direct route, and its 3.13 window to the end of 2029 is the longest published for that line. It does not cover 3.12 or earlier, whose commercial dates have passed. Our OSSeva vs Broadcom Tanzu RabbitMQ comparison sets out the overlap, and Exit Tanzu covers moving off a Tanzu licence.
Amazon MQ
Amazon MQ suits teams that want AWS to run the brokers. It supports 3.13 on several instance families and 4.2 and 4.3 on mq.m7g only, with in-place upgrades from 3.13 to 4.2 and from 4.2 to 4.3. When a version reaches end of support on the service, AWS upgrades the brokers for you in the following 45 days, after at least 90 days' notice. It does not support RabbitMQ streams, and quorum is the default queue type on 4.2.
CloudAMQP
CloudAMQP is a hosted RabbitMQ specialist. In May 2025 it began phasing out versions earlier than 3.13 and made the latest 3.13.x the minimum for new clusters, while saying it would not force customers onto 4.x soon. That makes it a reasonable landing place for a team leaving self-managed 3.x that is not ready for 4.0's breaking changes.
Seventh State and OpenLogic
Seventh State is the RabbitMQ team within Erlang Solutions. It sells health checks, design workshops, 24/7 support plans and help with outages and data recovery, which suits teams that want RabbitMQ specialists on call. OpenLogic lists RabbitMQ among more than 400 supported technologies, so one contract can cover the broker with the rest of the stack. Neither publishes patched RabbitMQ builds. See OSSeva vs Seventh State and OSSeva vs OpenLogic.
OSSeva
OSSeva for RabbitMQ applies fixes to the community source you already run, so the cluster stays on real Apache-licensed RabbitMQ with no proprietary runtime. Each release ships with a validated Erlang/OTP version, and those Erlang builds are patched on their own cycle as well. Patch delivers quarterly fixes with out-of-cycle releases for CVSS 9 and above, signed with GPG and Sigstore. Assure adds an annual configuration and architecture audit, upgrade planning and a SOC 2, HIPAA and PCI attestation package. Operate adds 24/7 monitoring, a 15-minute P1 response and a named senior engineer, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. Pricing is per cluster, not per core.
How to choose
| Situation | Usual answer |
|---|---|
| On 4.3 and able to upgrade each time a new minor ships | Stay on community releases and track the next minor |
| On 3.13 or 4.x and want fixes from the RabbitMQ core team | Broadcom commercial support |
| Happy to hand the brokers to a cloud provider | Amazon MQ or CloudAMQP, accepting their upgrade schedule |
| On 3.8 to 3.12, which Broadcom no longer covers | OSSeva patched builds while the move to 3.13 or 4.x is planned |
| On 3.13 or 4.0 to 4.2, self-managed, without a Broadcom licence | OSSeva patched builds with the matching Erlang/OTP |
| Need operational help more than patches | Seventh State, OpenLogic or OSSeva Operate |
A move from 3.13 to 4.x removes classic mirrored queues, so the queue migration is usually the long pole. RabbitMQ 4.0 breaking changes, migrating mirrored queues to quorum queues and RabbitMQ and Erlang version compatibility cover the steps.
Where OSSeva fits
OSSeva covers self-managed RabbitMQ from 3.8 through 4.x, including the 3.8 to 3.12 lines Broadcom has dropped, and patches the Erlang/OTP runtime as part of the same engagement. RabbitMQ 3 extended support covers the 3.x estate in more detail, and the extended support vendor roundup compares OSSeva across other technologies.
Frequently asked questions
Best rabbitmq support providers
It depends on how you run it. For patches from the RabbitMQ core team, Broadcom. For managed brokers, Amazon MQ or CloudAMQP. For specialist consulting and 24/7 help, Seventh State. For patched builds of self-managed 3.x and 4.x lines, including versions Broadcom has dropped, OSSeva. OpenLogic suits teams that want one support contract across many open source technologies.
Which companies offer RabbitMQ commercial support besides Broadcom?
Seventh State, part of Erlang Solutions, sells RabbitMQ support plans and consultancy. Perforce OpenLogic sells RabbitMQ technical support. OSSeva ships patched RabbitMQ and Erlang/OTP builds with optional 24/7 operations. Amazon MQ and CloudAMQP support RabbitMQ as managed services.
Is there commercial support for RabbitMQ 3.13 after end of life?
Yes. Community support for 3.13 ended on 30 September 2024, and Broadcom lists commercial support to 31 December 2029. OSSeva also ships patched 3.13 builds for self-managed clusters, and Amazon MQ still runs 3.13 with no end date published.
Who provides CVE patches for RabbitMQ 3.13?
Broadcom, in commercial releases for licence holders, and OSSeva, in patched builds of community 3.13 paired with a supported Erlang/OTP. The last public community release is 3.13.7.
Is there commercial support for RabbitMQ 3.12 after end of life?
Not from Broadcom: its commercial support for 3.12 ended on 30 June 2025, and Amazon MQ ended 3.12 on 17 March 2025. OSSeva publishes patched 3.12 builds, along with 3.8 to 3.11.
Who provides support for old or unmaintained RabbitMQ versions?
For lines older than 3.13, OSSeva is the provider that publishes patched builds. Seventh State and OpenLogic can help you operate and upgrade an older cluster, but do not publish patches for it. CloudAMQP and Amazon MQ move hosted clusters onto 3.13 or later.
Best alternatives to commercial rabbitmq support
Running community RabbitMQ on the current minor and upgrading as each one ships costs nothing beyond the upgrade work. If you cannot keep pace, a managed service or a patched build from OSSeva keeps fixes flowing without a Broadcom licence.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.