RabbitMQ 4.2 end of life
RabbitMQ 4.2 left community support on 31 July 2026. The last public release was 4.2.9, on 20 July 2026. The release information page also lists 4.2.10, from 17 August 2026, but it is not a public release, and it carries fixes such as CVE-2026-67421 that 4.2.9 lacks. Broadcom lists commercial support to 30 June 2030. OSSeva ships patched 4.2 builds today.
- End of life
- 31 July 2026
- Released
- Oct 2025
- Final release
- 4.2.9 (last public release, 20 July 2026)
- Successor
- RabbitMQ 4.3
Date published by RabbitMQ release information. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 31 July 2026
- Public 4.2.x releases. 4.2.9 is the last one in the rabbitmq-server GitHub releases and in the website's list of open source tags.
- Public fixes for later advisories. CVE-2026-67420 and CVE-2026-67421, both published on 25 September 2026, affect every 4.2 release before 4.2.10.
- Nothing else changes on the Broadcom side, which lists commercial support for 4.2 until 30 June 2030, the longest date on the release information page.
What actually breaks in the upgrade
4.2 is the only door to 4.3
RabbitMQ's upgrade guide allows in-place upgrades to 4.3 only from 4.2.x, and the 4.3.0 release notes ask for the latest 4.2 patch release first. That makes 4.2 a required stop for every 4.0, 4.1 and 3.13 cluster on the way to 4.3.
Enable Khepri before 4.3
4.2 made Khepri the default metadata store for new clusters only. Upgraded clusters keep Mnesia until khepri_db is enabled. 4.3 removed Mnesia and requires the khepri_db feature flag, so a 4.2 cluster still on Mnesia has to switch before it can upgrade.
AMQP 1.0 durability changed in 4.2
From 4.2, an AMQP 1.0 message sent without a header section is treated as non-durable, as the AMQP 1.0 specification defines. Clients that relied on the old behaviour must set durable to true explicitly. RabbitMQ's own AMQP 1.0 client libraries already do.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to RabbitMQ 4.3 | One rolling upgrade from the latest 4.2 patch, after enabling Khepri and every stable feature flag. | Weeks | Engineering time | A short hop, but 4.3 community support itself ends on 30 November 2026. |
| OSSeva patched builds on 4.2 | Signed 4.2 builds with backported fixes for advisories published after 4.2.9. | Days | Subscription | Keeps the cluster patched on a line that most estates pass through anyway. |
| Broadcom commercial support | Commercial 4.2 releases, listed to 30 June 2030. | Procurement | Commercial subscription | The longest vendor date on any 4.x line, on Broadcom's terms. |
| Stay on public 4.2.9 | No public fixes since July 2026. | None | Zero now | Scanners already flag CVE-2026-67420 and CVE-2026-67421 against it. |
What OSSeva does for RabbitMQ 4.2
OSSeva patches this line
OSSeva ships patched, signed RabbitMQ 4.2 builds now, with backported fixes for advisories published after 4.2.9, such as CVE-2026-67421 in the management UI. They are available on the Patch, Assure and Operate tiers, and OSSeva engineers run the Khepri switch and the move to 4.3 when the cluster is ready.
RabbitMQ extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A runtime, framework or broker with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
RabbitMQ 4.2: common questions
When did RabbitMQ 4.2 reach end of life?
Community support ended on 31 July 2026. Broadcom lists commercial support for 4.2 until 30 June 2030.
What is the last public RabbitMQ 4.2 release?
4.2.9, released on 20 July 2026. 4.2.10 appears on the release information page with a date of 17 August 2026, but it is not in the public GitHub releases or the list of open source tags.
Which Erlang version does RabbitMQ 4.2 need?
4.2.9 and 4.2.10 require Erlang 27.0 and support up to 27.x. Earlier 4.2 releases accept Erlang 26.2. Erlang 28 is supported for brand new clusters only, because of a known issue with rolling upgrades.
Can I get security patches for RabbitMQ 4.2?
Yes. OSSeva ships patched, signed 4.2 builds today on the Patch, Assure and Operate tiers.
Still running RabbitMQ 4.2?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.