End of life

RabbitMQ 4.1 end of life

RabbitMQ 4.1 left community support on 31 January 2026, and Broadcom lists commercial support until 30 April 2027. The last public release was 4.1.8, on 22 January 2026. Advisories published since then, including CVE-2026-57216, are fixed only in commercial 4.1 releases. Reaching 4.3 takes two upgrades, through 4.2. OSSeva ships patched 4.1 builds today.

End of life
31 January 2026
Released
Apr 2025
Final release
4.1.8 (last public release, 22 January 2026)
Successor
RabbitMQ 4.3, via 4.2

Date published by RabbitMQ release information. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 31 January 2026

  • Public 4.1.x releases. 4.1.8 was the last.
  • Public fixes for later advisories. CVE-2026-57216, which can let a loopback-restricted user such as guest connect remotely through a trusted PROXY protocol path, is fixed in 4.1.11. CVE-2026-57213, a stored XSS on the Federation Status page, is fixed in 4.1.10. Neither release is public.
  • Commercial support from Broadcom on 30 April 2027.

What actually breaks in the upgrade

Two hops to 4.3

RabbitMQ's upgrade table lists 4.1.x to 4.2.x, and upgrades to 4.3 only from 4.2.x. A 4.1 cluster moves to the latest 4.2 patch first, enables every stable feature flag, then moves to 4.3. A Blue/Green deployment to a new 4.3 cluster replaces the chain with one migration.

Khepri decides the second hop

4.3 has no Mnesia. A 4.1 cluster that still uses Mnesia must enable the khepri_db feature flag, on 4.1 or on 4.2, before the upgrade to 4.3. Khepri needs a majority of nodes online, so check cluster sizing and maintenance procedures first.

Erlang moves with the broker

4.1 runs on Erlang 26.2 to 27.x. Erlang 26 is no longer supported, and the latest 4.2 releases require Erlang 27.0. Move 4.1 nodes to Erlang 27 first so the runtime is not a second change during the broker upgrade.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to RabbitMQ 4.3Rolling upgrades from 4.1 to 4.2, then 4.2 to 4.3, with Khepri enabled on the way.WeeksEngineering timeThe destination, with the caveat that 4.3 community support ends on 30 November 2026.
OSSeva patched builds on 4.1Signed 4.1 builds with backported fixes for advisories published after 4.1.8.DaysSubscriptionKeeps the cluster patched through and after Broadcom's April 2027 date.
Broadcom commercial supportCommercial 4.1 releases, listed to 30 April 2027.ProcurementCommercial subscriptionSeven months of runway from today, on Broadcom's terms.
Stay on public 4.1.8No public fixes since January 2026.NoneZero nowNVD rates CVE-2026-57216 at 10.0. A poor advisory to carry on a broker.

What OSSeva does for RabbitMQ 4.1

OSSeva patches this line

OSSeva ships patched, signed RabbitMQ 4.1 builds now, with backported fixes for advisories published after 4.1.8, including CVE-2026-57216 and CVE-2026-57213. They are available on the Patch, Assure and Operate tiers, and they continue after Broadcom's commercial 4.1 support ends on 30 April 2027.

RabbitMQ extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A runtime, framework or broker with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library

RabbitMQ 4.1: common questions

When did RabbitMQ 4.1 reach end of life?

Community support ended on 31 January 2026. Broadcom lists commercial support until 30 April 2027. The last public release was 4.1.8, on 22 January 2026.

Can I upgrade RabbitMQ 4.1 directly to 4.3?

Not in place. 4.3 accepts upgrades only from 4.2.x, so the path is 4.1 to 4.2, then 4.2 to 4.3. A Blue/Green deployment to a new 4.3 cluster avoids the chain.

Which CVEs affect RabbitMQ 4.1.8?

Among others, CVE-2026-57216 (fixed in 4.1.11) and CVE-2026-57213 (fixed in 4.1.10). Both fixes shipped in commercial releases after community support ended.

Can I get security patches for RabbitMQ 4.1?

Yes. OSSeva ships patched, signed 4.1 builds today on the Patch, Assure and Operate tiers.

Still running RabbitMQ 4.1?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.