// OSSeva Blog
OperationsWho Provides Extended Support for Apache Tomcat 8.5 and 9.0?
The short answer
For Tomcat 8.5, which Apache retired on 31 March 2024, four providers publish patched builds: HeroDevs, Perforce OpenLogic, whose long-term support runs to 31 December 2028, TuxCare, for named 8.5.100 builds, and OSSeva. For Tomcat 9.0, Apache supports the line until 31 March 2027 and then continues the javax-based 9.x series on a new 9.1.x branch until 31 December 2030, so most 9.0 users have an upstream path without a Jakarta migration. TuxCare and OSSeva also cover 9.0 itself, and Red Hat supports its own Tomcat 9 build in JBoss Web Server 5 through extended life cycle phases to 2030.
The question to settle first is whether you can move from 9.0 to 9.1. Its main difference is that the APR/native connectors are gone, so estates that rely on them, or that cannot take any minor version change, are the ones that still need extended support for 9.0.
Which Tomcat versions Apache still supports
The Tomcat project's "Which version do I want?" page lists three supported lines, and on 11 February 2026 it announced the end of 9.0.x support.
| Line | Status on 6 October 2026 | Latest or final release | Java |
|---|---|---|---|
| 11.0.x | Supported | 11.0.26 | 17 and later |
| 10.1.x | Supported | 10.1.60 | 11 and later |
| 9.0.x | Supported until 31 March 2027; a 9.1.x branch continues until 31 December 2030 | 9.0.122 | 8 and later |
| 10.0.x | End of life since 31 October 2022 | 10.0.27 | 8 and later |
| 8.5.x | End of life since 31 March 2024 | 8.5.100 | 7 and later |
| 7.0.x | End of life since 31 March 2021 | 7.0.109 | 6 and later |
After 31 March 2027, Apache says 9.0.x releases are highly unlikely and security reports will not be checked against that branch, and the 9.0.x downloads come off the mirrors after 30 June 2027. The 9.1.x branch keeps the javax namespace but drops the APR/native connectors for HTTP, HTTPS and AJP, and Tomcat Native 1.3.x. Tomcat 9 end of support and 9.1 covers the change in detail, the Tomcat end-of-life chart tracks every line, and Tomcat CVE fixed versions lists which releases fix what.
Apache Tomcat support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | Tomcat versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| HeroDevs Never-Ending Support | Drop-in patched Tomcat with security fixes after end of life | 8.5 | Maven or Gradle dependency updates | Yes |
| Perforce OpenLogic | Long-term support with patches within 14 days for critical CVEs and 30 days for high, plus Tomcat technical support at Gold, Silver and Bronze levels | 8.5 LTS through 31 December 2028; technical support for other versions | LTS and support subscriptions | Yes |
| TuxCare Endless Lifecycle Support | Patched builds covering Coyote, Catalina, Jasper and Cluster, with a 14-day target for CVSS 7.0 and above | Named builds: 7.0.70 and 7.0.109; 8.5.100; 9.0.46 to 9.0.100; 10.1.18 and 10.1.42 | tar.gz and zip from TuxCare's repository, or Maven and Gradle artifacts | Yes |
| Red Hat JBoss Web Server | Red Hat's own tested Tomcat distribution with support phases and extended life cycle support (ELS) | JWS 7 (Tomcat 11): full support to 30 November 2029. JWS 6 (Tomcat 10.1): full to 30 November 2026, maintenance to 30 November 2028. JWS 5 (Tomcat 9): ELS to 31 July 2027 and a second ELS phase to 31 December 2030 | Red Hat subscription | Yes, on Red Hat's distribution |
| OSSeva | Backported CVE fixes with priority for EncryptInterceptor and classloader issues; hardening and connector audits on Assure; 24/7 JVM and Tomcat operations on Operate | 8.5.x and 10.0.x now; 9.0.x after 31 March 2027; covers Tomcat embedded in Spring Boot under Spring Boot coverage | Signed Docker images, apt and yum packages and zip archives | Yes |
Two rows need care. TuxCare lists exact builds, so check that yours is one of them, or plan a move to one. Red Hat supports the Tomcat inside JBoss Web Server, so a team running Apache's own binaries is covered only after moving onto Red Hat's distribution.
How the providers differ
Apache's 9.1.x branch
For most Tomcat 9.0 users, the first option to consider costs nothing. The 9.1.x branch carries the javax-based 9.x line to the end of 2030, so applications that do not use the APR/native connectors can move to it as a minor upgrade. Apache encourages moving from APR to the NIO connectors and, longer term, to newer Tomcat versions with its Jakarta EE migration tool.
HeroDevs
HeroDevs covers one Tomcat line, 8.5, as a drop-in replacement delivered through build files. That fits teams that build Tomcat into their applications with Maven or Gradle. See OSSeva vs HeroDevs for the wider overlap.
Perforce OpenLogic
OpenLogic is the one broad vendor with a published end date for 8.5: its long-term support runs to 31 December 2028, with patches within 14 days for critical CVEs and 30 days for high. It also sells technical support for Tomcat at all three levels, so one contract can cover Tomcat with Spring and the rest of the stack. See OSSeva vs OpenLogic.
TuxCare
TuxCare publishes the widest version list, from 7.0 to 10.1, but as specific builds rather than whole lines, with a 14-day target for fixes at CVSS 7.0 and above. It is a strong fit if you run one of those builds, or can standardise on one. See OSSeva vs TuxCare.
Red Hat
JBoss Web Server is Red Hat's own tested Tomcat distribution, with components such as mod_cluster. JWS 7, released in July 2026, ships Tomcat 11, JWS 6 ships Tomcat 10.1, and JWS 5 ships Tomcat 9. If you already hold Red Hat middleware subscriptions, it publishes dated life cycles for each Tomcat generation it ships, as long as you run Red Hat's builds.
OSSeva
OSSeva for Apache Tomcat backports fixes to the line you run, on your current JDK, including Java 8 for 8.5 and 9.0. Patch delivers quarterly fixes as signed Docker images, apt and yum packages and zip archives, with priority for EncryptInterceptor and classloader advisories. Assure adds a security hardening review, an HTTP, HTTPS and AJP connector audit, a SOC 2 and PCI DSS attestation package, a JVM upgrade sequencing plan and a Tomcat 10 and 11 migration assessment. Operate adds 24/7 JVM and Tomcat monitoring, a 15-minute P1 response, a named senior Tomcat engineer and execution of the major version migration, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. Tomcat embedded in a Spring Boot application OSSeva covers needs no separate engagement. Pricing is per application server.
How to choose
| Situation | Usual answer |
|---|---|
| On 9.0 with NIO connectors and able to take a minor upgrade | Move to Apache's 9.1.x branch, supported to 31 December 2030 |
| On 9.0 and dependent on the APR/native connectors | Move to NIO, or extended support for 9.0 from OSSeva or TuxCare after March 2027 |
| On 8.5, embedded through Maven or Gradle | HeroDevs, OpenLogic or OSSeva |
| On 8.5 as a standalone server, one vendor for many technologies | OpenLogic LTS to December 2028, or OSSeva |
| On a TuxCare-listed build | TuxCare |
| Already on Red Hat middleware subscriptions | JBoss Web Server |
| On 8.5 or 10.0 and ready for Jakarta | Upgrade to 10.1 or 11 |
The move to 10.1 or 11 is the javax to jakarta rename across every servlet-touching dependency. The Tomcat 9 to 10.1 migration guide covers the steps, and Tomcat end of life and the Jakarta namespace covers running extended support while it happens.
Where OSSeva fits
OSSeva covers Tomcat 8.5 and 10.0 today and 9.0 after Apache's support ends, alongside the Spring, messaging and data layers those applications depend on. See the extended support vendor roundup for how OSSeva compares across other technologies.
Frequently asked questions
Which companies offer Apache Tomcat support besides the original vendor?
HeroDevs, Perforce OpenLogic, TuxCare and OSSeva publish patched builds for end-of-life Tomcat, and Red Hat supports its own Tomcat in JBoss Web Server. OpenLogic also sells general Tomcat technical support. The Apache Tomcat project itself sells no support.
Who offers extended support for Apache Tomcat 8.5?
HeroDevs, OpenLogic, whose LTS runs to 31 December 2028, TuxCare, for the 8.5.100 build, and OSSeva. Apache's last 8.5 release was 8.5.100, and the line reached end of life on 31 March 2024.
Who provides CVE patches for Apache Tomcat 9 after March 2027?
Apache itself, through the 9.1.x branch, which continues until 31 December 2030 without the APR/native connectors. For 9.0 builds specifically, TuxCare covers named 9.0 releases, OSSeva backports to 9.0 after Apache's support ends, and Red Hat supports Tomcat 9 in JBoss Web Server 5 through ELS phases to 31 December 2030.
Is there commercial support for Apache Tomcat 8.5 after end of life?
Yes. OpenLogic's long-term support covers 8.5 to 31 December 2028, and HeroDevs, TuxCare and OSSeva publish patched 8.5 builds.
Should we move to Tomcat 9.1 or to Tomcat 10.1?
9.1 if you need more time on javax and do not use the APR/native connectors. 10.1 or 11 if you can complete the Jakarta migration, since that is where the project's long-term development is.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.