OSSEVA FOR MONGODB

MongoDB 4.2 to 6.0 — patched past end of life.

Committed security coverage for self-managed MongoDB lines past end of life, plus a planned route through the feature-compatibility upgrades to a supported release.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

MongoDB 5.0 and later need AVX

On x86_64, MongoDB 5.0 and later require the AVX instruction set. Older hardware and some hypervisor CPU models, such as the generic kvm64 profile, do not expose AVX, so mongod typically crashes on start with an illegal instruction error. Estates on that hardware are held on 4.4 until the platform changes.

Upgrades go one major version at a time

MongoDB requires each major version to be installed in turn, with featureCompatibilityVersion raised at every step. Moving from 4.4 to 7.0 means three full upgrades of every replica set and sharded cluster, each with its own driver compatibility checks.

Post-EOL fixes are discretionary

MongoDB's support policy carries no obligation to support versions past end of life. It has shipped some post-EOL releases, such as the December 2025 fixes for CVE-2025-14847, but 4.2 and earlier received no fix for that known-exploited flaw at all. Estates that need a commitment, not a hope, need someone contracted to deliver it.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
4.2(No upstream fix for CVE-2025-14847)EOLClean
4.4(Last line that runs without AVX)EOLClean
5.0(Patched by OSSeva)EOLClean
6.0(Patched by OSSeva)EOLClean
7.0(Supported upstream)CurrentClean
8.0(Supported upstream)CurrentClean

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Security fixes for MongoDB 4.2 to 6.0.

  • Backported security fixes for mongod, mongos and the bundled tools
  • 4.2 and 4.4 builds for hardware without AVX
  • Packages and container images
  • Signed artifacts and SBOMs
  • Advisory notifications
  • Upgrade planning
  • 24/7 managed operations
Get started →
Most popular

OSSeva Assure

Patch plus security review and an upgrade plan.

  • Everything in Patch
  • Authentication, TLS and network exposure review
  • featureCompatibilityVersion upgrade plan
  • Driver compatibility audit
  • SOC 2 / PCI DSS evidence pack
  • 24/7 managed operations
Get started →

OSSeva Operate

Managed operations for self-managed MongoDB.

  • Everything in Assure
  • 24/7 replica set and cluster monitoring
  • 15-minute P1 incident response
  • Named MongoDB engineer
  • Executed major version upgrades
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Check the CPU before upgrading to 5.0+bash
# MongoDB 5.0+ on x86_64 needs AVX. Empty output means this host cannot run it.
grep -o -m1 '\bavx\b' /proc/cpuinfo

# Current version and feature compatibility version
mongosh --quiet --eval 'db.version(); db.adminCommand({getParameter:1, featureCompatibilityVersion:1})'

Migrate from MongoDB Enterprise Advanced

MongoDB's commercial support covers its supported releases. For self-managed Community Server estates held on end-of-life versions by hardware, drivers or certification, OSSeva patches the version you run while the upgrade is planned.

↗

Pricing model

Priced per replica set or cluster. Contact for scoping.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Which versions of RabbitMQ are past community end-of-life?

RabbitMQ 3.8.x, 3.9.x, 3.10.x, 3.11.x, and 3.12.x have all reached community EOL — meaning no further security patches or CVE fixes are released by the RabbitMQ maintainers for those versions. RabbitMQ 3.13.x reached EOL in late 2024. OSSeva delivers backported CVE patches for 3.11 through 3.13.

Which PostgreSQL versions are no longer receiving community security patches?

PostgreSQL 9.6 through 13 have all reached community EOL. PostgreSQL 11 reached EOL November 2023, PostgreSQL 12 reached EOL November 2024, and PostgreSQL 13 reaches EOL November 2025. OSSeva provides extended security patching for PostgreSQL 11, 12, and 13 for teams that cannot immediately migrate to PG 14 or later.

Is Spring Framework 5.3.x still supported?

Spring Framework 5.3.x reached its community OSS EOL on December 31, 2024. Broadcom's commercial support for Spring 5.3.x is also no longer available under standard terms. OSSeva delivers backported CVE patches for Spring Framework 5.3.x and Spring Boot 2.7.x under our extended lifecycle support program.

Which versions of Apache Kafka are EOL?

Apache Kafka versions 2.x and 3.0 through 3.4 are past their community supported window, meaning no further patch releases. Kafka 3.5 and 3.6 have reached or are approaching EOL. OSSeva supports Kafka 2.8 through 3.5 with backported security patches and compliance documentation.

What happened to Redis licensing? Can I still use Redis for free?

In March 2024, Redis Ltd. moved Redis off BSD-3-Clause to a dual licence of RSALv2 and SSPLv1 — not, despite widespread reporting, the Business Source License, which is a different licence with a time-delayed conversion that RSALv2 does not have. From Redis 8, Redis added AGPLv3 as a third option, so current Redis is available under an OSI-approved licence again. Valkey, the Linux Foundation fork created eight days after the change, continues under BSD-3-Clause. Redis 7.2 and earlier remain BSD-licensed, and OSSeva maintains CVE-patched builds of 6.2.x and 7.0.x for teams staying on them.

Is Node.js 18 still receiving security patches?

Node.js 18 (LTS 'Hydrogen') reached its end-of-life date in April 2025 and no longer receives security releases from the Node.js project. OSSeva delivers CVE patches for Node.js 18 for enterprise teams that have not yet migrated to Node.js 20 or 22.

Is Apache Tomcat 8.5 still supported?

Apache Tomcat 8.5 reached its community EOL in March 2024. OSSeva provides extended security patching for Tomcat 8.5.x for teams running Java EE 7 workloads that cannot immediately migrate to Tomcat 9.0 or 10.1.

What .NET versions does OSSeva support?

.NET 6 reached Microsoft end-of-support in November 2024. .NET 7 reached EOL in May 2024. OSSeva delivers CVE patches for .NET 6 and .NET 7 for teams that have not yet migrated to .NET 8 (LTS, supported through November 2026).

Ready to get MongoDB patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.