Back to blog

// OSSeva Blog

Operations

Tomcat 9 End of Support and the New 9.1.x Branch Explained

Matt Reynolds5 min read

The short answer

The Apache Tomcat project has announced that support for Tomcat 9.0.x ends on 31 March 2027. Tomcat 9 does not simply stop there. Shortly before that date the project will start a new 9.1.x branch, and releases from 9.1.x will continue until 31 December 2030. For most users the move from 9.0.x to 9.1.x is a normal point release upgrade.

The exception is anyone using the APR/native connectors. They are not available in 9.1.x, so those users have configuration work to do first.

Why Tomcat 9 gets extended support

Tomcat 9 is the last major Tomcat version that supports Java EE. Tomcat 10 and later implement Jakarta EE, where the APIs moved from javax.* to jakarta.*. Because many applications cannot make that change quickly, the Tomcat community decided to support Tomcat 9 beyond the ten years major versions usually get.

VersionPlatformMin JavaStatus
Tomcat 11.0.xJakarta EE 1117Supported
Tomcat 10.1.xJakarta EE 1011Supported
Tomcat 9.0.xJava EE 88End of support 31 Mar 2027
Tomcat 8.5.xJava EE 77EOL 31 Mar 2024

What changes in 9.1.x

  • The APR/native connectors for HTTP, HTTPS and AJP are removed. Move to the NIO HTTP and NIO AJP connectors, and for TLS to NIO+JSSE or NIO+OpenSSL.
  • Tomcat Native 1.3.x is not supported. NIO+OpenSSL continues through Tomcat Native 2.0.x.
  • Security fixes, bug fixes and features continue to be back-ported as they were for 9.0.x.

What happens after 31 March 2027

New 9.0.x releases become highly unlikely, and security reports are no longer checked against the 9.0.x branch. After 30 June 2027 the 9.0.x download links and documentation are removed from tomcat.apache.org, though old releases stay in the archive. Note that the Which Version page still says 9.0 support ends "no earlier than" 31 March 2027 and gives no 9.1.x end date; the dated end-of-support announcement is more specific.

Upgrade or stay on 9.1.x?

The Tomcat project itself encourages Tomcat 9 users to upgrade rather than settle on 9.1.x, using the Tomcat Migration Tool for Jakarta EE. If your application and its libraries can move to jakarta, target Tomcat 10.1 or 11. If they cannot, 9.1.x buys time until the end of 2030. Keep patching either way: CVE-2025-24813, a path equivalence flaw in the default servlet fixed in 9.0.99, 10.1.35 and 11.0.3, has been on CISA's Known Exploited Vulnerabilities catalogue since 1 April 2025.

Estates still on Tomcat 8.5, or on vendor builds pinned to old 9.0.x releases, get neither path. OSSeva backports Tomcat security fixes to those versions; see Apache Tomcat support, the Tomcat 9 and Tomcat 8.5 end-of-life pages, and Tomcat CVEs in enterprise Java.

Frequently asked questions

How long will Tomcat 9 be supported?

The 9.0.x branch until 31 March 2027, and the 9.1.x branch until 31 December 2030.

What is the difference between Tomcat 9 and 10?

Tomcat 9 implements Java EE 8 with javax.* packages. Tomcat 10 and later implement Jakarta EE with jakarta.* packages, so applications must be migrated, as covered in our javax to jakarta migration guide.

What is the latest Tomcat 9 version?

9.0.122, according to tomcat.apache.org at the time of writing.

Tags

Apache TomcatTomcat 9End of LifeJakarta EEJava

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.