Erlang/OTP 24 end of life
Erlang/OTP 24 reached end of life on 10 May 2024. It is the oldest OTP line still widely found in production, and the one with the most accumulated exposure: 22 CVE records have been disclosed against it since that date, including CVE-2025-32433 at CVSS 10.0.
- End of life
- 10 May 2024
- Released
- May 2021
- Final release
- 24.3.4.17
- Successor
- OTP 27 or OTP 28
Date published by Erlang/OTP release policy, cross-checked against endoflife.date. We do not publish a lifecycle date we cannot source.
What actually stops on 10 May 2024
- Security patches for the OTP 24 branch
- Any further 24.x releases — 24.3.4.17 was the last
- Support for running current RabbitMQ releases on this runtime
What actually breaks in the upgrade
This line carries the most measured exposure
Our exposure study counted 22 CVE records disclosed against OTP 24 after its end-of-life date, nine of them CVSS 7.0 or higher. That is not a projection — each identifier is listed and links to its own page. If you are on OTP 24, this is the most quantified risk on the site.
CVE-2025-32433 is the one to look at first
A pre-authentication remote code execution flaw in the Erlang/OTP SSH application, scored CVSS 10.0. If the SSH application is enabled anywhere in your deployment, that is the advisory to assess before any planning conversation.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Move to a supported OTP release | Upgrade the runtime to OTP 27 or 28. | Coordinated with the broker | Engineering time | The right destination. The constraint is that each RabbitMQ release supports a narrow band of OTP versions, so the runtime rarely moves alone. |
| Stay and accept the exposure | Keep the current OTP release with no security updates. | None | None until an audit or an incident | Common and rarely deliberate. The version still reports fine and passes inventory checks, which is exactly why it persists. |
| OSSeva extended support | Patched builds on the OTP line you already run. | Drop-in package or image | Per cluster | Keeps the broker/runtime pair intact while the upgrade is planned properly rather than executed against an audit deadline. |
What OSSeva does for Erlang/OTP 24
OSSeva patches this line
OSSeva ships patched OTP 24 builds. Given the volume of post-EOL advisories against this line, it is the one we most often find unpatched during scoping.
Erlang/OTP extended supportWhat your auditor will say
Requires that system components are protected from known vulnerabilities via security patches. A runtime with no upstream patch stream cannot satisfy this on its own, and the runtime is in scope even when the assessor only asked about the broker.
Vulnerability identification and remediation. Identification is satisfied by scanning; remediation is what fails when the fix does not exist for your release line.
Erlang/OTP 24: common questions
How many CVEs affect Erlang/OTP 24 since it went end of life?
22 CVE records disclosed after 10 May 2024 still name the 24 line, nine of them scoring CVSS 7.0 or above and the highest at 10.0. The identifiers and the method are published in our EOL exposure study.
What is CVE-2025-32433?
A pre-authentication remote code execution vulnerability in the Erlang/OTP SSH application, scored CVSS 10.0 and published in April 2025. It is the highest-severity advisory in this set.
Still running Erlang/OTP 24?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.