Apache Tomcat 7 end of life
Apache Tomcat 7 reached end of life on 31 March 2021, and 7.0.109 was the last release. Tomcat advisories still list 7.0 as known affected: four CVEs made public on 23 September 2026, including CVE-2026-76183, a WebSocket security constraint bypass, name 7.0 with no fix. Moving to Tomcat 9.0 keeps the javax namespace and needs Java 8.
- End of life
- 31 March 2021
- Released
- Jun 2010
- Final release
- 7.0.109 (April 2021)
- Successor
- Tomcat 9.0 (javax) or Tomcat 10.1 and 11.0 (jakarta)
Date published by Apache Tomcat 7.0.x end-of-life notice. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 31 March 2021
- Releases from the 7.0.x branch. 7.0.109 was the last, and the branch was made read-only.
- Checks of security reports against 7.0.x. Where the Tomcat team does name 7.0 in an advisory, it lists it as end of life and known affected, with no fix.
- Bug fixes for issues that affect only 7.0.x, and the 7.0.x Bugzilla project, which was made read-only.
What actually breaks in the upgrade
The September 2026 CVEs
Four Tomcat CVEs made public on 23 September 2026 list 7.0 as known affected: CVE-2026-76183 (WebSocket security constraint bypass, from 7.0.43), CVE-2026-78383 (AJP denial of service, all 7.0), CVE-2026-79677 (WebSocket denial of service, from 7.0.43) and CVE-2026-87022 (WebSocket message smuggling with per-message-deflate, from 7.0.56). Fixes exist only in 9.0.122, 10.1.60 and 11.0.26.
Earlier 2026 CVEs land on 7.0 too
CVE-2026-65182 (security constraint bypass with overlapping path constraints) and CVE-2026-68569 (DataSourceRealm authentication failing open) were published on 25 August 2026 and cover 7.0.0 to 7.0.109. A 7.0 server below 7.0.100 is also exposed to Ghostcat, CVE-2020-1938, which has been on CISA's Known Exploited Vulnerabilities catalogue since 3 March 2022.
Tomcat 9.0 is the javax route
Tomcat 7 implements Servlet 3.0 and runs on Java 6 and later. Tomcat 9.0 implements Servlet 4.0, still in the javax namespace, and needs Java 8. Tomcat 10.1 and 11.0 use jakarta, so every servlet import changes. Tomcat 9.0 support ends on 31 March 2027, with releases continuing on a 9.1.x branch to 31 December 2030.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Tomcat 9.0 | javax namespace kept, Java 8 or later. | Weeks | Engineering time | The shortest route to fixed code for an application that cannot change namespace yet. |
| Migrate to Tomcat 10.1 or 11.0 | Jakarta EE namespace, Java 11 or 17. | Weeks to quarters | Code and dependency changes | The long-term destination. Every library that touches the servlet API has to move with it. |
| Harden 7.0 while you move | Disable unused AJP connectors and WebSocket endpoints, and restrict network reach. | Days | Engineering time | Shrinks the exposure from the 2026 CVEs, but closes none of them. |
| Stay unpatched | No upstream releases since April 2021. | None | Zero now | Every new advisory that names 7.0 adds an open finding. |
What OSSeva does for Apache Tomcat 7
OSSeva supports this line
OSSeva's patched Tomcat builds cover 8.5.x, 9.0.x and 10.0.x, not 7.0. For Tomcat 7 estates, the Assure tier provides the connector configuration audit, hardening review and migration assessment, and the Operate tier runs the move to 9.0 or 10.1, where patched builds take over.
Apache Tomcat extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
US federal agencies must remediate KEV-listed vulnerabilities by the catalogue deadline. Ghostcat, CVE-2020-1938, is on the list and affects Tomcat 7.0 before 7.0.100.
Apache Tomcat 7: common questions
When did Apache Tomcat 7 reach end of life?
On 31 March 2021. The Tomcat team announced the date a year ahead, and 7.0.109 was the last release.
Is Tomcat 7 affected by CVE-2026-76183?
Yes. The advisory lists 7.0.43 to 7.0.109 as end of support but known affected. It lets an attacker bypass the security constraints on WebSocket endpoints. The fix exists only in 9.0.122, 10.1.60 and 11.0.26.
Can I upgrade Tomcat 7 to 9 without changing to jakarta?
Yes. Tomcat 9.0 keeps the javax namespace. It needs Java 8 or later, and its own support ends on 31 March 2027, with a 9.1.x branch after that.
What Java version does Tomcat 7 need?
Java 6 or later, or Java 7 and later for WebSocket support, according to the Tomcat versions page.
Does OSSeva patch Tomcat 7?
No. OSSeva ships patched builds for Tomcat 8.5, 9.0 and 10.0, and supports Tomcat 7 estates with hardening and the migration onto one of those lines.
Still running Apache Tomcat 7?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.