RabbitMQ 3.8 end of life
RabbitMQ 3.8 reached end of life on 31 July 2022, according to the RabbitMQ release series page. The first release shipped on 1 October 2019 and the last, 3.8.35, on 9 July 2022. Its final releases run on Erlang/OTP 23.2 to 24.3, both out of support. OSSeva ships patched, signed RabbitMQ 3.8 builds for clusters that cannot move yet.
- End of life
- 31 July 2022
- Released
- Oct 2019
- Final release
- 3.8.35 (9 July 2022)
- Successor
- RabbitMQ 4.3, via 3.9 to 3.13, or a Blue/Green move
Date published by RabbitMQ release series (archived September 2022). We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 31 July 2022
- Patch releases on the 3.8.x line. 3.8.35 was the last.
- Fixes for later advisories. CVE-2023-46118, a denial of service through oversized HTTP API messages, was patched in 3.11.24 and 3.12.7 only.
- Erlang runtime updates. The last 3.8 releases need Erlang/OTP 23.2 to 24.3, and neither series is still patched by the Erlang project.
What actually breaks in the upgrade
Six hops to reach 4.x
Rolling upgrades move one release series at a time, so a 3.8 cluster passes through 3.9, 3.10, 3.11, 3.12 and 3.13 before 4.x, with feature flags enabled at each step. A Blue/Green deployment to a new 4.x cluster replaces the chain with one migration, at the cost of running two clusters for a while.
Mirrored queues end at 4.0
RabbitMQ 3.8 introduced quorum queues, but many 3.8 clusters still run mirrored classic queues. RabbitMQ 4.0 removed classic queue mirroring, so those queues move to quorum queues or streams before the cluster can run 4.x. That queue migration usually sets the timeline.
Erlang moves at every step
3.8 tops out at Erlang 24.3 and 3.13 runs on Erlang 26, so the runtime moves during the chain. From Erlang 26, TLS client peer verification is on by default, so TLS-enabled Shovels, Federation links and LDAP connections need checking on the way through.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to RabbitMQ 4.3 | Rolling upgrades through every series to 3.13, then 4.x, with the queue migration on the way. | Months | Engineering time | The destination. Plan the mirrored queue migration first. |
| Blue/Green to a new 4.x cluster | Build a current cluster and move publishers and consumers across. | Weeks | Parallel infrastructure plus engineering time | Usually faster than six rolling hops from 3.8. |
| OSSeva patched builds on 3.8 | Signed 3.8 builds with backported CVE fixes for the broker and its Erlang runtime. | Days | Subscription | Keeps the cluster patched and auditable while the migration runs on your timeline. |
| Stay unpatched | No public fixes since July 2022. | None | Zero now | A broker sits in the path of every integration it serves. |
What OSSeva does for RabbitMQ 3.8
OSSeva patches this line
OSSeva ships patched, signed RabbitMQ 3.8 builds on the Patch, Assure and Operate tiers, with CVE backports where they are feasible and documented mitigations where they are not. OSSeva engineers also run the mirrored to quorum queue migration and the move to 4.x.
RabbitMQ extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
RabbitMQ 3.8: common questions
When did RabbitMQ 3.8 reach end of life?
On 31 July 2022. The last release was 3.8.35, on 9 July 2022.
Which Erlang version does RabbitMQ 3.8 need?
It depends on the patch release. 3.8.29 and later support Erlang/OTP 23.2 to 24.3. The first 3.8 releases started at Erlang 21.3, and the minimum rose during the series.
Can I upgrade RabbitMQ 3.8 straight to 4.x?
Not with a rolling upgrade, which moves one series at a time. A Blue/Green deployment to a new 4.x cluster is the way to skip the intermediate versions.
Did RabbitMQ 3.8 have quorum queues?
Yes. Quorum queues arrived in 3.8.0, along with feature flags. Many 3.8 clusters still use mirrored classic queues, which RabbitMQ 4.0 removed.
Can I get security patches for RabbitMQ 3.8?
Yes. OSSeva ships patched, signed 3.8 builds today on the Patch, Assure and Operate tiers.
Still running RabbitMQ 3.8?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.