// Apache Pulsar extended support

Pulsar long-term support is running out.
OSSeva patches the 2.10 to 3.2 lines the project no longer maintains.

Apache Pulsar 4.0 LTS leaves active support on 21 October 2026 and gets security fixes only until 21 October 2027. Pulsar 3.0 LTS lost security support on 2 May 2026, and every 2.x line stopped years earlier. Support for 4.1 and 4.2 has also ended, and 5.0 has only milestone builds so far. OSSeva ships patched, signed builds for Pulsar 2.10, 2.11, 3.0, 3.1 and 3.2, with the ZooKeeper under them in the same subscription.

Pulsar 3.0 LTS3.23.12.112.10ZooKeeper under Pulsar

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Pulsar clusters stay on old lines

Pulsar is three systems that upgrade together: brokers, BookKeeper and the metadata store. That makes every move a project.

LTS windows are shorter than upgrade cycles

The release policy gives an LTS line 24 months of active support and 36 months of security support, and a feature release 6 months of each. Pulsar 3.0 shipped in May 2023 and was out of security support by May 2026. Any cluster that settled on a feature release such as 3.1 or 3.2 lost fixes after six months.

The 2.x lines upgrade one step at a time

Before 3.0, the project requires a linear upgrade through every feature version, so a 2.10 cluster passes through 2.11 on its way to 3.0. Live upgrade and rollback between LTS lines starts at 3.0, and even then the policy rules out jumping from 3.2 straight to 5.0.

The next LTS is not ready for production

Pulsar 5.0 has published 5.0.0-M1 in June 2026 and 5.0.0-M2 in September 2026. The project says milestone releases are not meant for production and may break compatibility before the final LTS release, and it does not maintain them.

The dates that matter

  1. 2023-04-18

    Pulsar 2.10 reaches the end of support. The last release is 2.10.6.

  2. 2023-05-02

    Pulsar 3.0.0 LTS released.

  3. 2024-01-11

    Pulsar 2.11 reaches the end of support. The last release is 2.11.4.

  4. 2024-10-21

    Pulsar 4.0.0 LTS released.

  5. 2025-05-02

    Pulsar 3.0 LTS active support ends. Security fixes continue.

  6. 2026-05-02

    Pulsar 3.0 LTS security support ends. 3.0.17, from April 2026, is the last release.

  7. 2026-09-24

    Pulsar 4.2 support ends, six months after its release.

  8. 2026-10-21

    Pulsar 4.0 LTS active support ends. Security fixes continue until 21 October 2027.

What OSSeva delivers

1

Patched Pulsar 2.10 to 3.2

CVE fixes for the broker, BookKeeper and the ZooKeeper dependency on the Pulsar line you run, delivered as GPG-signed artifacts through Docker and Helm, with a notification when a new CVE affects your version.

OSSeva Patch2.10 to 3.2Signed builds
2

Security and compliance review

An audit of tenant and namespace isolation, a review of JWT and TLS authentication and of geo-replication security, and a SOC 2 and HIPAA attestation package for the cluster as it runs today.

OSSeva AssureMulti-tenant auditSOC 2 and HIPAA
3

24/7 Pulsar operations

Monitoring of brokers, bookies and ZooKeeper around the clock, backlog and consumer lag alerting, a 15-minute response on P1 incidents and a named senior Pulsar engineer. Pulsar Functions and IO connectors are in scope.

OSSeva Operate24/715-minute P1

Your options, compared

OptionWhat you getTrade-off
Upgrade to 4.0 LTSSecurity fixes until 21 October 2027A rolling upgrade of brokers, BookKeeper and the metadata store, and another LTS decision within a year.
Wait for 5.0 LTSA new LTS line once the final release shipsMilestone builds only so far, and no direct path from 3.2 or older lines.
OSSeva extended supportPatched 2.10 to 3.2 builds now, with ZooKeeper includedA subscription for as long as you keep the old line.
Stay unpatchedNothingNew Pulsar, BookKeeper and ZooKeeper advisories stay open, and scanners flag the version every week.

Support dates, last releases, release semantics, upgrade rules and the milestone release policy from the Apache Pulsar release policy page (pulsar.apache.org/contribute/release-policy), checked on 4 October 2026. Release dates for 3.0.17 and the 5.0 milestones cross-checked against the apache/pulsar GitHub releases. Coverage from the OSSeva Apache Pulsar technology page.

Frequently asked questions

How long is a Pulsar LTS release supported?

The release policy gives LTS releases 24 months of active support and 36 months of security support. Feature releases get 6 months of each. Under active support the project fixes bugs and security issues; under security support it fixes security issues only.

When does Pulsar 4.0 LTS support end?

Active support ends on 21 October 2026 and security support on 21 October 2027. The latest 4.0 release is 4.0.13, from August 2026.

Is Pulsar 3.0 still supported?

No. Pulsar 3.0 LTS left active support on 2 May 2025 and security support on 2 May 2026. The last release was 3.0.17. OSSeva ships patched 3.0 builds.

Can I upgrade Pulsar 2.10 straight to 4.0?

No. Before 3.0 the project requires a linear upgrade through each feature version, so 2.10 goes to 2.11 and then 3.0. From 3.0, upgrading from one LTS to the next, such as 3.0 to 4.0, is supported.

Will the Pulsar project patch older versions?

Only on a best-effort basis. The release policy says the project may make ad hoc releases for older versions when resources allow or a CVE is severe, and notes that commercial vendors may offer paid support for previous versions.

Does OSSeva support Pulsar without ZooKeeper?

Yes. OSSeva supports Pulsar 3.x clusters on ZooKeeper and on the Oxia metadata store.

Keep Pulsar patched while you plan the next LTS move.

Talk to an engineer about your Pulsar version, its metadata store and your upgrade path.