End of life

RabbitMQ 3.8 end of life

RabbitMQ 3.8 reached end of life on 31 July 2022, according to the RabbitMQ release series page. The first release shipped on 1 October 2019 and the last, 3.8.35, on 9 July 2022. Its final releases run on Erlang/OTP 23.2 to 24.3, both out of support. OSSeva ships patched, signed RabbitMQ 3.8 builds for clusters that cannot move yet.

End of life
31 July 2022
Released
Oct 2019
Final release
3.8.35 (9 July 2022)
Successor
RabbitMQ 4.3, via 3.9 to 3.13, or a Blue/Green move

Date published by RabbitMQ release series (archived September 2022). We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 31 July 2022

  • Patch releases on the 3.8.x line. 3.8.35 was the last.
  • Fixes for later advisories. CVE-2023-46118, a denial of service through oversized HTTP API messages, was patched in 3.11.24 and 3.12.7 only.
  • Erlang runtime updates. The last 3.8 releases need Erlang/OTP 23.2 to 24.3, and neither series is still patched by the Erlang project.

What actually breaks in the upgrade

Six hops to reach 4.x

Rolling upgrades move one release series at a time, so a 3.8 cluster passes through 3.9, 3.10, 3.11, 3.12 and 3.13 before 4.x, with feature flags enabled at each step. A Blue/Green deployment to a new 4.x cluster replaces the chain with one migration, at the cost of running two clusters for a while.

Mirrored queues end at 4.0

RabbitMQ 3.8 introduced quorum queues, but many 3.8 clusters still run mirrored classic queues. RabbitMQ 4.0 removed classic queue mirroring, so those queues move to quorum queues or streams before the cluster can run 4.x. That queue migration usually sets the timeline.

Erlang moves at every step

3.8 tops out at Erlang 24.3 and 3.13 runs on Erlang 26, so the runtime moves during the chain. From Erlang 26, TLS client peer verification is on by default, so TLS-enabled Shovels, Federation links and LDAP connections need checking on the way through.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to RabbitMQ 4.3Rolling upgrades through every series to 3.13, then 4.x, with the queue migration on the way.MonthsEngineering timeThe destination. Plan the mirrored queue migration first.
Blue/Green to a new 4.x clusterBuild a current cluster and move publishers and consumers across.WeeksParallel infrastructure plus engineering timeUsually faster than six rolling hops from 3.8.
OSSeva patched builds on 3.8Signed 3.8 builds with backported CVE fixes for the broker and its Erlang runtime.DaysSubscriptionKeeps the cluster patched and auditable while the migration runs on your timeline.
Stay unpatchedNo public fixes since July 2022.NoneZero nowA broker sits in the path of every integration it serves.

What OSSeva does for RabbitMQ 3.8

OSSeva patches this line

OSSeva ships patched, signed RabbitMQ 3.8 builds on the Patch, Assure and Operate tiers, with CVE backports where they are feasible and documented mitigations where they are not. OSSeva engineers also run the mirrored to quorum queue migration and the move to 4.x.

RabbitMQ extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library Every RabbitMQ version and end-of-life date

RabbitMQ 3.8: common questions

When did RabbitMQ 3.8 reach end of life?

On 31 July 2022. The last release was 3.8.35, on 9 July 2022.

Which Erlang version does RabbitMQ 3.8 need?

It depends on the patch release. 3.8.29 and later support Erlang/OTP 23.2 to 24.3. The first 3.8 releases started at Erlang 21.3, and the minimum rose during the series.

Can I upgrade RabbitMQ 3.8 straight to 4.x?

Not with a rolling upgrade, which moves one series at a time. A Blue/Green deployment to a new 4.x cluster is the way to skip the intermediate versions.

Did RabbitMQ 3.8 have quorum queues?

Yes. Quorum queues arrived in 3.8.0, along with feature flags. Many 3.8 clusters still use mirrored classic queues, which RabbitMQ 4.0 removed.

Can I get security patches for RabbitMQ 3.8?

Yes. OSSeva ships patched, signed 3.8 builds today on the Patch, Assure and Operate tiers.

Still running RabbitMQ 3.8?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.