// MongoDB extended support

MongoDB 6.0 and earlier are end of life.
Some of your hardware can't run anything newer.

MongoDB supports each major release for a fixed window, and 4.2, 4.4, 5.0 and 6.0 are all past it. Any fixes after that are at MongoDB's discretion. Moving forward means one major upgrade at a time, and from 5.0 onward a CPU with AVX. OSSeva patches the self-managed versions you run while the hardware and the upgrades catch up.

MongoDB 4.24.45.06.0Community ServerReplica setsSharded clusters

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why MongoDB estates are stuck

A MongoDB upgrade is rarely one step, and sometimes it is blocked by the hardware underneath.

The AVX trap

On x86_64, MongoDB 5.0 and later require the AVX instruction set. Older servers, and virtual machines using a generic CPU model such as kvm64, do not expose AVX, so mongod typically crashes with an illegal instruction error. Those estates cannot leave 4.4 until the platform changes.

One major version at a time

MongoDB upgrades pass through every major release, raising featureCompatibilityVersion at each step. Going from 4.4 to 7.0 is three upgrades of every replica set and shard, each with its own driver checks.

Drivers and applications move too

Newer server versions drop support for old wire protocol versions and old drivers. Applications pinned to an old driver have to be updated before the server can move.

The dates that matter

  1. 2024-02-29

    MongoDB 4.4 end of life.

  2. 2024-10-31

    MongoDB 5.0 end of life.

  3. 2025-07-31

    MongoDB 6.0 end of life.

  4. 2025-12-29

    CVE-2025-14847, unauthenticated heap memory disclosure through compressed messages, is added to CISA's KEV catalog. Fixed in 4.4.30 and later lines; no fix for 4.2, 4.0 or 3.6.

  5. 2027-08-31

    MongoDB 7.0 end of life.

What OSSeva delivers

1

Patched MongoDB builds

Committed security fixes for self-managed MongoDB 4.2 to 6.0, including the 4.2 and 4.4 lines that run without AVX, delivered as packages and images.

4.2–6.0Non-AVXSigned
2

Exposure review

Authentication, TLS and network exposure checks for every mongod and mongos, because an internet-reachable database is the most common MongoDB incident.

AuthTLSNetwork
3

Upgrade programme

Hardware and hypervisor checks for AVX, driver audits, and each featureCompatibilityVersion step planned and rehearsed.

AVX checkFCV stepsDrivers

Your options, compared

OptionWhat you getTrade-off
Upgrade to 7.0 or 8.0A supported MongoDB releaseSeveral sequential upgrades, AVX-capable hardware, and driver updates.
MongoDB ELS Add-OnUp to two years of support for one minor version after EOLAn add-on to Enterprise Advanced, not available for Community Server.
Move to MongoDB AtlasA managed, upgraded serviceA migration and a new cost model; not an option for every data residency requirement.
OSSeva extended supportPatched self-managed 4.4 to 6.0A subscription while you upgrade.
Stay unpatchedNothingExposed MongoDB is one of the most scanned targets on the internet.

Dates from MongoDB's lifecycle schedules and download index; AVX requirement from MongoDB's production notes; KEV date from CISA.

Frequently asked questions

Why does MongoDB 5.0 say it requires a CPU with AVX support?

MongoDB 5.0 and later require the AVX instruction set on x86_64. If the processor, or the CPU model the hypervisor exposes, lacks AVX, mongod crashes on start, and the official Docker image warns that MongoDB 5.0+ requires a CPU with AVX support. Run it on AVX-capable hardware, pass AVX through from the hypervisor, or stay on 4.4 with extended support.

Does MongoDB still patch 4.4, 5.0 and 6.0?

Sometimes. MongoDB has published post-EOL releases, most recently 4.4.31, 5.0.34 and 6.0.29 in June 2026, but its support policy carries no obligation to do so, and 4.2 got no fix for CVE-2025-14847. For a committed SLA, MongoDB sells an Extended Lifecycle Support add-on to Enterprise Advanced customers; OSSeva provides committed coverage for Community Server.

Do you support MongoDB Atlas?

No. Atlas is managed and patched by MongoDB. We support self-managed Community Server.

What about the SSPL?

MongoDB Community Server is under the Server Side Public License. Running it for your own applications is the common case and is what we support; offering MongoDB as a service to third parties carries SSPL obligations regardless of who supports it.

Patch the MongoDB you can't upgrade yet.

Discovery call, estate and hardware inventory, proposal within five working days.