Back to blog

// OSSeva Blog

Operations

Who Provides Extended Support for Apache Tomcat 8.5 and 9.0?

Matt Reynolds9 min read

The short answer

For Tomcat 8.5, which Apache retired on 31 March 2024, four providers publish patched builds: HeroDevs, Perforce OpenLogic, whose long-term support runs to 31 December 2028, TuxCare, for named 8.5.100 builds, and OSSeva. For Tomcat 9.0, Apache supports the line until 31 March 2027 and then continues the javax-based 9.x series on a new 9.1.x branch until 31 December 2030, so most 9.0 users have an upstream path without a Jakarta migration. TuxCare and OSSeva also cover 9.0 itself, and Red Hat supports its own Tomcat 9 build in JBoss Web Server 5 through extended life cycle phases to 2030.

The question to settle first is whether you can move from 9.0 to 9.1. Its main difference is that the APR/native connectors are gone, so estates that rely on them, or that cannot take any minor version change, are the ones that still need extended support for 9.0.

Which Tomcat versions Apache still supports

The Tomcat project's "Which version do I want?" page lists three supported lines, and on 11 February 2026 it announced the end of 9.0.x support.

LineStatus on 6 October 2026Latest or final releaseJava
11.0.xSupported11.0.2617 and later
10.1.xSupported10.1.6011 and later
9.0.xSupported until 31 March 2027; a 9.1.x branch continues until 31 December 20309.0.1228 and later
10.0.xEnd of life since 31 October 202210.0.278 and later
8.5.xEnd of life since 31 March 20248.5.1007 and later
7.0.xEnd of life since 31 March 20217.0.1096 and later

After 31 March 2027, Apache says 9.0.x releases are highly unlikely and security reports will not be checked against that branch, and the 9.0.x downloads come off the mirrors after 30 June 2027. The 9.1.x branch keeps the javax namespace but drops the APR/native connectors for HTTP, HTTPS and AJP, and Tomcat Native 1.3.x. Tomcat 9 end of support and 9.1 covers the change in detail, the Tomcat end-of-life chart tracks every line, and Tomcat CVE fixed versions lists which releases fix what.

Apache Tomcat support providers compared

Each row reflects what the provider publishes on its own site as of 6 October 2026.

ProviderWhat it coversTomcat versionsDelivery modelSelf-managed?
HeroDevs Never-Ending SupportDrop-in patched Tomcat with security fixes after end of life8.5Maven or Gradle dependency updatesYes
Perforce OpenLogicLong-term support with patches within 14 days for critical CVEs and 30 days for high, plus Tomcat technical support at Gold, Silver and Bronze levels8.5 LTS through 31 December 2028; technical support for other versionsLTS and support subscriptionsYes
TuxCare Endless Lifecycle SupportPatched builds covering Coyote, Catalina, Jasper and Cluster, with a 14-day target for CVSS 7.0 and aboveNamed builds: 7.0.70 and 7.0.109; 8.5.100; 9.0.46 to 9.0.100; 10.1.18 and 10.1.42tar.gz and zip from TuxCare's repository, or Maven and Gradle artifactsYes
Red Hat JBoss Web ServerRed Hat's own tested Tomcat distribution with support phases and extended life cycle support (ELS)JWS 7 (Tomcat 11): full support to 30 November 2029. JWS 6 (Tomcat 10.1): full to 30 November 2026, maintenance to 30 November 2028. JWS 5 (Tomcat 9): ELS to 31 July 2027 and a second ELS phase to 31 December 2030Red Hat subscriptionYes, on Red Hat's distribution
OSSevaBackported CVE fixes with priority for EncryptInterceptor and classloader issues; hardening and connector audits on Assure; 24/7 JVM and Tomcat operations on Operate8.5.x and 10.0.x now; 9.0.x after 31 March 2027; covers Tomcat embedded in Spring Boot under Spring Boot coverageSigned Docker images, apt and yum packages and zip archivesYes

Two rows need care. TuxCare lists exact builds, so check that yours is one of them, or plan a move to one. Red Hat supports the Tomcat inside JBoss Web Server, so a team running Apache's own binaries is covered only after moving onto Red Hat's distribution.

How the providers differ

Apache's 9.1.x branch

For most Tomcat 9.0 users, the first option to consider costs nothing. The 9.1.x branch carries the javax-based 9.x line to the end of 2030, so applications that do not use the APR/native connectors can move to it as a minor upgrade. Apache encourages moving from APR to the NIO connectors and, longer term, to newer Tomcat versions with its Jakarta EE migration tool.

HeroDevs

HeroDevs covers one Tomcat line, 8.5, as a drop-in replacement delivered through build files. That fits teams that build Tomcat into their applications with Maven or Gradle. See OSSeva vs HeroDevs for the wider overlap.

Perforce OpenLogic

OpenLogic is the one broad vendor with a published end date for 8.5: its long-term support runs to 31 December 2028, with patches within 14 days for critical CVEs and 30 days for high. It also sells technical support for Tomcat at all three levels, so one contract can cover Tomcat with Spring and the rest of the stack. See OSSeva vs OpenLogic.

TuxCare

TuxCare publishes the widest version list, from 7.0 to 10.1, but as specific builds rather than whole lines, with a 14-day target for fixes at CVSS 7.0 and above. It is a strong fit if you run one of those builds, or can standardise on one. See OSSeva vs TuxCare.

Red Hat

JBoss Web Server is Red Hat's own tested Tomcat distribution, with components such as mod_cluster. JWS 7, released in July 2026, ships Tomcat 11, JWS 6 ships Tomcat 10.1, and JWS 5 ships Tomcat 9. If you already hold Red Hat middleware subscriptions, it publishes dated life cycles for each Tomcat generation it ships, as long as you run Red Hat's builds.

OSSeva

OSSeva for Apache Tomcat backports fixes to the line you run, on your current JDK, including Java 8 for 8.5 and 9.0. Patch delivers quarterly fixes as signed Docker images, apt and yum packages and zip archives, with priority for EncryptInterceptor and classloader advisories. Assure adds a security hardening review, an HTTP, HTTPS and AJP connector audit, a SOC 2 and PCI DSS attestation package, a JVM upgrade sequencing plan and a Tomcat 10 and 11 migration assessment. Operate adds 24/7 JVM and Tomcat monitoring, a 15-minute P1 response, a named senior Tomcat engineer and execution of the major version migration, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. Tomcat embedded in a Spring Boot application OSSeva covers needs no separate engagement. Pricing is per application server.

How to choose

SituationUsual answer
On 9.0 with NIO connectors and able to take a minor upgradeMove to Apache's 9.1.x branch, supported to 31 December 2030
On 9.0 and dependent on the APR/native connectorsMove to NIO, or extended support for 9.0 from OSSeva or TuxCare after March 2027
On 8.5, embedded through Maven or GradleHeroDevs, OpenLogic or OSSeva
On 8.5 as a standalone server, one vendor for many technologiesOpenLogic LTS to December 2028, or OSSeva
On a TuxCare-listed buildTuxCare
Already on Red Hat middleware subscriptionsJBoss Web Server
On 8.5 or 10.0 and ready for JakartaUpgrade to 10.1 or 11

The move to 10.1 or 11 is the javax to jakarta rename across every servlet-touching dependency. The Tomcat 9 to 10.1 migration guide covers the steps, and Tomcat end of life and the Jakarta namespace covers running extended support while it happens.

Where OSSeva fits

OSSeva covers Tomcat 8.5 and 10.0 today and 9.0 after Apache's support ends, alongside the Spring, messaging and data layers those applications depend on. See the extended support vendor roundup for how OSSeva compares across other technologies.

Frequently asked questions

Which companies offer Apache Tomcat support besides the original vendor?

HeroDevs, Perforce OpenLogic, TuxCare and OSSeva publish patched builds for end-of-life Tomcat, and Red Hat supports its own Tomcat in JBoss Web Server. OpenLogic also sells general Tomcat technical support. The Apache Tomcat project itself sells no support.

Who offers extended support for Apache Tomcat 8.5?

HeroDevs, OpenLogic, whose LTS runs to 31 December 2028, TuxCare, for the 8.5.100 build, and OSSeva. Apache's last 8.5 release was 8.5.100, and the line reached end of life on 31 March 2024.

Who provides CVE patches for Apache Tomcat 9 after March 2027?

Apache itself, through the 9.1.x branch, which continues until 31 December 2030 without the APR/native connectors. For 9.0 builds specifically, TuxCare covers named 9.0 releases, OSSeva backports to 9.0 after Apache's support ends, and Red Hat supports Tomcat 9 in JBoss Web Server 5 through ELS phases to 31 December 2030.

Is there commercial support for Apache Tomcat 8.5 after end of life?

Yes. OpenLogic's long-term support covers 8.5 to 31 December 2028, and HeroDevs, TuxCare and OSSeva publish patched 8.5 builds.

Should we move to Tomcat 9.1 or to Tomcat 10.1?

9.1 if you need more time on javax and do not use the APR/native connectors. 10.1 or 11 if you can complete the Jakarta migration, since that is where the project's long-term development is.

Tags

Apache TomcatEnd of LifeExtended SupportJakarta EEVendor Comparison

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.