Apache Pulsar 4.0 LTS end of life
Apache Pulsar 4.0 LTS leaves active support on 21 October 2026 and keeps security support until 21 October 2027, according to the Pulsar release policy. 4.0.0 shipped on 21 October 2024 and the latest release is 4.0.13, from 3 August 2026. Support for 4.1 and 4.2 has already ended, and 5.0, the next LTS, has only milestone releases.
- End of life
- 21 October 2027
- Released
- Oct 2024
- Final release
- 4.0.13 (latest, 3 August 2026)
- Successor
- Apache Pulsar 5.0 LTS (milestone releases only so far)
Date published by Apache Pulsar release policy. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 21 October 2027
- Bug-fix releases on 21 October 2026. From that day the release policy lists 4.0 in security support only, so fixes for broker, BookKeeper and client bugs go to newer releases.
- Active support for any Pulsar line. 4.1 support ended on 8 March 2026 and 4.2 support ended on 24 September 2026. 5.0 has published only milestone builds, and the project does not maintain those.
- Security fixes on 21 October 2027. After that, the policy says older lines may get ad hoc releases on a best-effort basis, with no commitment.
What actually breaks in the upgrade
Plan for 5.0, not 4.2
Feature releases get six months of support, and 4.2 is already past it. The release policy supports live upgrade and downgrade between one LTS and the next, so the planned move from 4.0 is 5.0.0 once it ships. No date for 5.0.0 has been published.
Milestones are for testing
The policy says each milestone is built from a temporary branch that is dropped after the next milestone or the final LTS release. 5.0.0-M2, released in September 2026, will get no fixes. Test your clients and functions against it, but keep production on 4.0.
Three layers move together
A Pulsar upgrade touches brokers, BookKeeper and the metadata store. Upgrade each layer in a rolling sequence, test the rollback path in staging, and check client library versions before the brokers move.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Stay on 4.0 with upstream security releases | Security fixes continue to 21 October 2027. | None | Zero now | Workable for a year if security fixes are enough. Bug fixes stop on 21 October 2026. |
| Upgrade to 5.0 LTS | The next LTS, with live upgrade supported from 4.0. | Weeks | Engineering time | The destination, once 5.0.0 is released and tested. |
| OSSeva patched builds on 4.0 | Signed 4.0 builds with backported bug and security fixes. | Days | Subscription | Covers the bug fixes the project stops on 21 October 2026 and continues after October 2027. |
| Move to a feature release | 4.1 and 4.2 are both out of support. | Weeks | Engineering time | Not an option today. There is no supported feature release to move to. |
What OSSeva does for Apache Pulsar 4.0 LTS
OSSeva patches this line
OSSeva ships patched, signed Pulsar 4.0 builds across the broker, BookKeeper and metadata layers, with backported bug fixes after active support ends on 21 October 2026 and security fixes after 21 October 2027. They are available on the Patch, Assure and Operate tiers, and OSSeva engineers run the move to 5.0 when the cluster is ready.
Apache Pulsar extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Apache Pulsar 4.0 LTS: common questions
When does Apache Pulsar 4.0 reach end of life?
Active support ends on 21 October 2026 and security support ends on 21 October 2027. 4.0 is an LTS release, which the policy supports for 24 months of active support and 36 months of security support.
What is the difference between active support and security support?
Under active support the project fixes bugs and security issues. Under security support it fixes security issues only. From 21 October 2026, Pulsar 4.0 is in security support only.
Which Pulsar versions are supported after October 2026?
Only 4.0, and only for security fixes. 4.1 and 4.2 support has ended, and 5.0 has milestone releases only. The release policy does not treat milestones as maintained releases.
Can Pulsar 4.0 upgrade directly to 5.0?
Yes. The release policy supports live upgrade and downgrade between one LTS and the next, and 5.0.0 will be the next LTS.
Who patches Pulsar 4.0 after its support ends?
OSSeva ships patched, signed 4.0 builds on the Patch, Assure and Operate tiers.
Still running Apache Pulsar 4.0 LTS?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.