// Apache Tomcat support
Tomcat 9 end of life starts with 9.0 on 31 March 2027.
Apache Tomcat support for the line each server runs, whether it moves to 9.1, 10.1 or 11, or stays where it is.
OSSeva provides Apache Tomcat support for 8.5, 9.0, 10.0, 10.1 and 11, including patched builds for 8.5 and 10.0 now and for 9.0 after Apache's support for it ends on 31 March 2027. The Apache Tomcat team has announced that Tomcat 9 continues on a new 9.1.x branch until 31 December 2030, and for many servers that move is no harder than a point release. The hard cases are servers that use the APR/native connectors, which 9.1.x drops, applications still on 8.5 or 10.0, and teams that want one support contract for Tomcat and the rest of their stack. Support is priced per application server.
Trusted globally by enterprises




Where Tomcat estates get stuck
Apache has given Tomcat 9 a long runway. The problems sit in the places that runway does not reach.
9.1.x drops the APR/native connectors
Shortly before 9.0.x support ends, Tomcat 9 releases move to a 9.1.x branch without the APR/native connectors for HTTP, HTTPS and AJP. Tomcat Native 1.3.x support also ends on 31 March 2027. Servers that rely on those connectors switch to the NIO connectors first, and HTTPS listeners need their TLS setup tested again.
Tomcat 8.5 and 10.0 are already out
Apache ended support for 8.5 on 31 March 2024, with 8.5.100 as the final release, and for 10.0 on 31 October 2022. Neither line gets fixes from the project, and both often sit under third-party WARs that nobody can rebuild.
Leaving Tomcat 9 means the jakarta rename
Tomcat 10 and later moved the servlet API from javax.* to jakarta.*, so leaving the 9.x line changes code and every servlet-related dependency, not just configuration. Apache points Tomcat 9 users to its migration tool for Jakarta EE to help with that move.
The dates that matter
2022-10-31
Tomcat 10.0.x reaches end of life. Apache directs users to 10.1.x or later.
2024-03-31
Tomcat 8.5.x support ends. 8.5.100 is the final release.
2026-02-11
The Apache Tomcat team announces the Tomcat 9 long-term support plan and the end of Tomcat Native 1.3.x support.
2027-03-31
Tomcat 9.0.x and Tomcat Native 1.3.x support end. Tomcat 9 releases continue on the 9.1.x branch.
2030-12-31
Planned end of releases from the Tomcat 9.1.x branch.
What OSSeva delivers
Patched Tomcat 8.5, 9.0 and 10.0 builds
Signed builds with security fixes backported to 8.5 and 10.0 today, and to 9.0 after Apache's support ends on 31 March 2027, for applications that cannot move to 9.1.x. Delivered for Docker, apt, yum or zip installs.
Hardening and migration planning
A Tomcat security configuration review, an audit of the HTTP, HTTPS and AJP connectors, a JVM upgrade sequencing plan, a Tomcat 10 and 11 migration assessment, and a SOC 2 and PCI DSS attestation package.
Tomcat operated around the clock
24/7 JVM and Tomcat health monitoring, thread pool, connection pool, GC and heap alerting, a 15-minute P1 incident response SLA, a named senior Tomcat engineer, and execution of the major version migration when you are ready.
Tomcat on the JDK you run
Coverage for Tomcat 8.5 and 9.0 on Java 8, so the servlet container and the JDK do not have to change in the same release. Tomcat embedded in a Spring Boot application covered by OSSeva is included in that Spring Boot coverage.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Move to Tomcat 9.1.x | Free Apache releases for the javax-based 9.x line until 31 December 2030 | No APR/native connectors, so servers that use them switch to NIO first. For most teams on 9.0 this is the right next step. |
| Upgrade to Tomcat 10.1 or 11 | The current Apache lines and no 9.x end date to plan around | The javax to jakarta change touches application code and every servlet-related dependency. |
| A platform that bundles Tomcat | Tomcat patched as part of a product its vendor or cloud provider supports | Coverage follows that platform's version list, which may not match the Tomcat on your own servers. |
| OSSeva Tomcat support | Support for 8.5 to 11, with patched 8.5 and 10.0 builds now and 9.0 builds after March 2027 | A subscription priced per application server. |
| Stay unpatched | Nothing | Tomcat is often the internet-facing tier, so open CVEs there are easy for scanners and attackers to find. |
Dates from the Apache Tomcat versions page, the Tomcat 8.5 end-of-life notice and the Apache Tomcat team's announcements of 11 February 2026 on the Tomcat 9 long-term support plan and the end of Tomcat Native 1.3.x, all checked on 9 October 2026. OSSeva coverage from the OSSeva Apache Tomcat technology page.
Frequently asked questions
When is Tomcat 9 end of life?
Tomcat 9.0.x support ends on 31 March 2027. Under the plan Apache announced on 11 February 2026, Tomcat 9 continues on a new 9.1.x branch with releases until 31 December 2030. Tomcat 8.5 has been end of life since 31 March 2024.
What changes between Tomcat 9.0 and 9.1?
Apache describes the differences as minimal. The APR/native connectors for HTTP, HTTPS and AJP are removed, and Tomcat Native 1.3.x is not supported. If you do not use Tomcat Native, or already run Native 2.0.x, moving from 9.0.x to 9.1.x works like a normal point release.
Who provides Apache Tomcat support?
The Apache Tomcat project ships releases and security fixes for its supported lines and answers questions on its mailing lists. Commercial support comes from vendors and cloud services that bundle Tomcat into their own platforms, and from third-party support companies for Tomcat you run yourself. OSSeva is a third-party option that covers 8.5 to 11 under one contract with the rest of your Java and data stack.
Is there extended support for Tomcat 8.5?
Yes, from third-party providers. Apache published 8.5.100 as the final 8.5 release and ended support on 31 March 2024. OSSeva ships signed 8.5 builds with security fixes backported, including on Java 8.
Can we get Tomcat 9.0 patches after 31 March 2027?
From Apache, only by moving to the 9.1.x branch. OSSeva backports fixes to 9.0.x for applications that cannot make that move, for example because they depend on the APR/native connectors.
Do we have to upgrade to Tomcat 10 or 11?
Not to keep getting Apache releases before 2031, because 9.1.x continues until 31 December 2030. Apache still encourages Tomcat 9 users to move to a later version, and the javax to jakarta change is most of that work. OSSeva Assure includes a Tomcat 10 and 11 migration assessment.
How is it priced?
Per application server. The tier you choose, Patch, Assure or Operate, sets what is included. Book a discovery call for a quote.
Know which Tomcat line each server should be on.
Book a discovery call with your Tomcat versions and connectors, and we will send a quote priced per application server.