OSSEVA FOR ELASTICSEARCH

Elasticsearch 7.x — patched after end of support.

Backported security fixes for Elasticsearch 7.10.2 and 7.17, with a planned route to 8.x or OpenSearch when your indices and clients are ready.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

7.10.2 is the last Apache-2.0 Elasticsearch

From 7.11 Elastic moved Elasticsearch to SSPL and the Elastic License, and 7.x never received the AGPL option added in 8.16. Teams that cannot accept the later licences, and products that embed Elasticsearch, have stayed on 7.10.2 ever since, and nobody upstream patches it.

8.x needs a reindex, not just an upgrade

Elasticsearch 8.x cannot read indices created in 6.x or earlier, removes mapping types, and enables security by default. Old indices have to be reindexed and clients updated, which is why so many clusters are still on 7.17.

Advisories keep landing with no 7.x fix

Elasticsearch 7.17 reached end of life on 15 January 2026, and 7.17.29 was its last release. CVE-2025-37731 (PKI realm user impersonation) and CVE-2025-68384 (node crash by a low-privileged user) affect every 7.x release and were fixed only in 8.19 and 9.x.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
7.10.2(Last Apache-2.0 release)ExtendedClean
7.17(EOL 15 Jan 2026; last release 7.17.29)ExtendedClean
8.x(Supported upstream)CurrentClean
OpenSearch 2.x(Migration target)CurrentClean

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Security fixes for Elasticsearch 7.10.2 and 7.17.

  • Backported security fixes for Elasticsearch and its bundled libraries
  • Bundled JDK updates
  • Packages and container images
  • Signed artifacts and SBOMs
  • Advisory notifications
  • Migration planning
Get started →
Most popular

OSSeva Assure

Patch plus security hardening and a migration plan.

  • Everything in Patch
  • Security and network exposure review
  • Reindex and client plan for 8.x or OpenSearch
  • SOC 2 / PCI DSS evidence pack
  • 24/7 managed operations
Get started →

OSSeva Operate

Managed operations for self-managed search clusters.

  • Everything in Assure
  • 24/7 cluster health monitoring
  • 15-minute P1 incident response
  • Executed migrations to 8.x or OpenSearch
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Find indices that block an 8.x upgradebash
# Indices created before 7.0 must be reindexed before 8.x
curl -s 'localhost:9200/_all/_settings/index.version.created*?pretty' | grep -B2 '"6'

# The upgrade assistant's deprecation report
curl -s 'localhost:9200/_migration/deprecations?pretty'

Migrate from Amazon OpenSearch Service Extended Support

AWS charges Extended Support on older Elasticsearch versions in OpenSearch Service. Self-managed clusters on patched 7.x builds avoid the surcharge while the migration is planned.

↗

Pricing model

Priced per cluster. Contact for scoping.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Which versions of RabbitMQ are past community end-of-life?

RabbitMQ 3.8.x, 3.9.x, 3.10.x, 3.11.x, and 3.12.x have all reached community EOL — meaning no further security patches or CVE fixes are released by the RabbitMQ maintainers for those versions. RabbitMQ 3.13.x reached EOL in late 2024. OSSeva delivers backported CVE patches for 3.11 through 3.13.

Which PostgreSQL versions are no longer receiving community security patches?

PostgreSQL 9.6 through 13 have all reached community EOL. PostgreSQL 11 reached EOL November 2023, PostgreSQL 12 reached EOL November 2024, and PostgreSQL 13 reaches EOL November 2025. OSSeva provides extended security patching for PostgreSQL 11, 12, and 13 for teams that cannot immediately migrate to PG 14 or later.

Is Spring Framework 5.3.x still supported?

Spring Framework 5.3.x reached its community OSS EOL on December 31, 2024. Broadcom's commercial support for Spring 5.3.x is also no longer available under standard terms. OSSeva delivers backported CVE patches for Spring Framework 5.3.x and Spring Boot 2.7.x under our extended lifecycle support program.

Which versions of Apache Kafka are EOL?

Apache Kafka versions 2.x and 3.0 through 3.4 are past their community supported window, meaning no further patch releases. Kafka 3.5 and 3.6 have reached or are approaching EOL. OSSeva supports Kafka 2.8 through 3.5 with backported security patches and compliance documentation.

What happened to Redis licensing? Can I still use Redis for free?

In March 2024, Redis Ltd. moved Redis off BSD-3-Clause to a dual licence of RSALv2 and SSPLv1 — not, despite widespread reporting, the Business Source License, which is a different licence with a time-delayed conversion that RSALv2 does not have. From Redis 8, Redis added AGPLv3 as a third option, so current Redis is available under an OSI-approved licence again. Valkey, the Linux Foundation fork created eight days after the change, continues under BSD-3-Clause. Redis 7.2 and earlier remain BSD-licensed, and OSSeva maintains CVE-patched builds of 6.2.x and 7.0.x for teams staying on them.

Is Node.js 18 still receiving security patches?

Node.js 18 (LTS 'Hydrogen') reached its end-of-life date in April 2025 and no longer receives security releases from the Node.js project. OSSeva delivers CVE patches for Node.js 18 for enterprise teams that have not yet migrated to Node.js 20 or 22.

Is Apache Tomcat 8.5 still supported?

Apache Tomcat 8.5 reached its community EOL in March 2024. OSSeva provides extended security patching for Tomcat 8.5.x for teams running Java EE 7 workloads that cannot immediately migrate to Tomcat 9.0 or 10.1.

What .NET versions does OSSeva support?

.NET 6 reached Microsoft end-of-support in November 2024. .NET 7 reached EOL in May 2024. OSSeva delivers CVE patches for .NET 6 and .NET 7 for teams that have not yet migrated to .NET 8 (LTS, supported through November 2026).

Ready to get Elasticsearch patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.