Apache Pulsar 3.0 LTS end of life
Apache Pulsar 3.0 LTS reached the end of security support on 2 May 2026, three years after its release. Active support had already ended on 2 May 2025. The final release on the line was 3.0.17. Security fixes now ship only for 4.0 LTS and later, and 4.0 LTS itself receives security fixes until 21 October 2027.
- End of life
- 2 May 2026
- Released
- May 2023
- Final release
- 3.0.17
- Successor
- Apache Pulsar 4.0 LTS
Date published by Apache Pulsar release policy. We do not publish a lifecycle date we cannot source.
What actually stops on 2 May 2026
- Releases on the 3.0.x line. 3.0.17 was the last.
- Security fixes for brokers, BookKeeper integration, functions and the bundled dependencies.
- Compatibility testing against newer clients and Java versions.
What actually breaks in the upgrade
4.0 LTS has its own clock
Pulsar 4.0 LTS active support ends on 21 October 2026 and security support on 21 October 2027. Upgrading from 3.0 now buys about a year of fixes before the next LTS decision.
Three systems, not one
A Pulsar upgrade touches brokers, BookKeeper and the metadata store. Plan the rolling upgrade for each layer, and check client compatibility before the brokers move.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to 4.0 LTS | Rolling upgrade of brokers, bookies and metadata store. | Weeks | Engineering time | The supported path, with another LTS decision in 2027. |
| Extended support on 3.0 | Backported security fixes for the 3.0 line. | Days | Subscription | For clusters that cannot take a multi-layer upgrade yet. |
| Stay unpatched | No fixes since May 2026. | None | Zero now | Pulsar carries a large dependency tree; transitive CVEs accumulate quickly. |
What OSSeva does for Apache Pulsar 3.0 LTS
OSSeva patches this line
OSSeva patches Pulsar 3.0 across the broker, BookKeeper and coordination layers and supports the move to 4.0 LTS.
Apache Pulsar extended supportWhat your auditor will say
CC7.1. A messaging platform outside its security support window is a finding without compensating controls.
Apache Pulsar 3.0 LTS: common questions
When did Apache Pulsar 3.0 reach end of life?
Security support ended on 2 May 2026. Active support ended a year earlier, on 2 May 2025. The last release was 3.0.17.
How long is Pulsar 4.0 LTS supported?
Active support until 21 October 2026 and security support until 21 October 2027.
Is there commercial support for end-of-life Pulsar versions?
Yes. OSSeva provides patched Pulsar 3.0 builds and support covering brokers, BookKeeper and the metadata layer.
Still running Apache Pulsar 3.0 LTS?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.