Approaching381 days from today

Apache Pulsar 4.0 LTS end of life

Apache Pulsar 4.0 LTS leaves active support on 21 October 2026 and keeps security support until 21 October 2027, according to the Pulsar release policy. 4.0.0 shipped on 21 October 2024 and the latest release is 4.0.13, from 3 August 2026. Support for 4.1 and 4.2 has already ended, and 5.0, the next LTS, has only milestone releases.

End of life
21 October 2027
Released
Oct 2024
Final release
4.0.13 (latest, 3 August 2026)
Successor
Apache Pulsar 5.0 LTS (milestone releases only so far)

Date published by Apache Pulsar release policy. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 21 October 2027

  • Bug-fix releases on 21 October 2026. From that day the release policy lists 4.0 in security support only, so fixes for broker, BookKeeper and client bugs go to newer releases.
  • Active support for any Pulsar line. 4.1 support ended on 8 March 2026 and 4.2 support ended on 24 September 2026. 5.0 has published only milestone builds, and the project does not maintain those.
  • Security fixes on 21 October 2027. After that, the policy says older lines may get ad hoc releases on a best-effort basis, with no commitment.

What actually breaks in the upgrade

Plan for 5.0, not 4.2

Feature releases get six months of support, and 4.2 is already past it. The release policy supports live upgrade and downgrade between one LTS and the next, so the planned move from 4.0 is 5.0.0 once it ships. No date for 5.0.0 has been published.

Milestones are for testing

The policy says each milestone is built from a temporary branch that is dropped after the next milestone or the final LTS release. 5.0.0-M2, released in September 2026, will get no fixes. Test your clients and functions against it, but keep production on 4.0.

Three layers move together

A Pulsar upgrade touches brokers, BookKeeper and the metadata store. Upgrade each layer in a rolling sequence, test the rollback path in staging, and check client library versions before the brokers move.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Stay on 4.0 with upstream security releasesSecurity fixes continue to 21 October 2027.NoneZero nowWorkable for a year if security fixes are enough. Bug fixes stop on 21 October 2026.
Upgrade to 5.0 LTSThe next LTS, with live upgrade supported from 4.0.WeeksEngineering timeThe destination, once 5.0.0 is released and tested.
OSSeva patched builds on 4.0Signed 4.0 builds with backported bug and security fixes.DaysSubscriptionCovers the bug fixes the project stops on 21 October 2026 and continues after October 2027.
Move to a feature release4.1 and 4.2 are both out of support.WeeksEngineering timeNot an option today. There is no supported feature release to move to.

What OSSeva does for Apache Pulsar 4.0 LTS

OSSeva patches this line

OSSeva ships patched, signed Pulsar 4.0 builds across the broker, BookKeeper and metadata layers, with backported bug fixes after active support ends on 21 October 2026 and security fixes after 21 October 2027. They are available on the Patch, Assure and Operate tiers, and OSSeva engineers run the move to 5.0 when the cluster is ready.

Apache Pulsar extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library Every Apache Pulsar version and end-of-life date

Apache Pulsar 4.0 LTS: common questions

When does Apache Pulsar 4.0 reach end of life?

Active support ends on 21 October 2026 and security support ends on 21 October 2027. 4.0 is an LTS release, which the policy supports for 24 months of active support and 36 months of security support.

What is the difference between active support and security support?

Under active support the project fixes bugs and security issues. Under security support it fixes security issues only. From 21 October 2026, Pulsar 4.0 is in security support only.

Which Pulsar versions are supported after October 2026?

Only 4.0, and only for security fixes. 4.1 and 4.2 support has ended, and 5.0 has milestone releases only. The release policy does not treat milestones as maintained releases.

Can Pulsar 4.0 upgrade directly to 5.0?

Yes. The release policy supports live upgrade and downgrade between one LTS and the next, and 5.0.0 will be the next LTS.

Who patches Pulsar 4.0 after its support ends?

OSSeva ships patched, signed 4.0 builds on the Patch, Assure and Operate tiers.

Still running Apache Pulsar 4.0 LTS?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.