End of life

Erlang/OTP 24 end of life

Erlang/OTP 24 reached end of life on 10 May 2024. It is the oldest OTP line still widely found in production, and the one with the most accumulated exposure: 22 CVE records have been disclosed against it since that date, including CVE-2025-32433 at CVSS 10.0.

End of life
10 May 2024
Released
May 2021
Final release
24.3.4.17
Successor
OTP 27 or OTP 28

Date published by Erlang/OTP release policy, cross-checked against endoflife.date. We do not publish a lifecycle date we cannot source.

What actually stops on 10 May 2024

  • Security patches for the OTP 24 branch
  • Any further 24.x releases — 24.3.4.17 was the last
  • Support for running current RabbitMQ releases on this runtime

What actually breaks in the upgrade

This line carries the most measured exposure

Our exposure study counted 22 CVE records disclosed against OTP 24 after its end-of-life date, nine of them CVSS 7.0 or higher. That is not a projection — each identifier is listed and links to its own page. If you are on OTP 24, this is the most quantified risk on the site.

CVE-2025-32433 is the one to look at first

A pre-authentication remote code execution flaw in the Erlang/OTP SSH application, scored CVSS 10.0. If the SSH application is enabled anywhere in your deployment, that is the advisory to assess before any planning conversation.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Move to a supported OTP releaseUpgrade the runtime to OTP 27 or 28.Coordinated with the brokerEngineering timeThe right destination. The constraint is that each RabbitMQ release supports a narrow band of OTP versions, so the runtime rarely moves alone.
Stay and accept the exposureKeep the current OTP release with no security updates.NoneNone until an audit or an incidentCommon and rarely deliberate. The version still reports fine and passes inventory checks, which is exactly why it persists.
OSSeva extended supportPatched builds on the OTP line you already run.Drop-in package or imagePer clusterKeeps the broker/runtime pair intact while the upgrade is planned properly rather than executed against an audit deadline.

What OSSeva does for Erlang/OTP 24

OSSeva patches this line

OSSeva ships patched OTP 24 builds. Given the volume of post-EOL advisories against this line, it is the one we most often find unpatched during scoping.

Erlang/OTP extended support

What your auditor will say

PCI DSS v4 Requirement 6

Requires that system components are protected from known vulnerabilities via security patches. A runtime with no upstream patch stream cannot satisfy this on its own, and the runtime is in scope even when the assessor only asked about the broker.

SOC 2 CC7

Vulnerability identification and remediation. Identification is satisfied by scanning; remediation is what fails when the fix does not exist for your release line.

Compliance library

Erlang/OTP 24: common questions

How many CVEs affect Erlang/OTP 24 since it went end of life?

22 CVE records disclosed after 10 May 2024 still name the 24 line, nine of them scoring CVSS 7.0 or above and the highest at 10.0. The identifiers and the method are published in our EOL exposure study.

What is CVE-2025-32433?

A pre-authentication remote code execution vulnerability in the Erlang/OTP SSH application, scored CVSS 10.0 and published in April 2025. It is the highest-severity advisory in this set.

Still running Erlang/OTP 24?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.