Apache Pulsar 5.0 · Version Status

Apache Pulsar 5.0 End of Life Date

Apache Pulsar 5.0 end-of-life date, support status, and CVE risk. Data reconciled from official vendor documentation and endoflife.date at every build; the source of each date is on the product page.

✓ Apache Pulsar 5.0 is actively supported. EOL date: October 5, 2028.
📅 Get reminded before Apache Pulsar 5.0 reaches EOL on October 5, 2028 — alerts 90, 30 & 7 days out.
Google →
✉️ Or get it by email — alerts at 90 / 60 / 30 / 7 days and on the day: Free · one-click unsubscribe in every email · no other mail, ever
EOL Date
Oct 5, 2028
725 days remaining
Latest Release
5.0.0
LTS release
Release Date
Oct 5, 2026
Apache Pulsar 5.0 series
Extended Support
Oct 5, 2029
Extended support
Lifecycle detail

Apache Pulsar 5.0 was released on October 5, 2026 and support is scheduled to end on October 5, 2028 — a planned supported lifespan of 2 years, in line with the 2 years median for Apache Pulsar LTS releases. It is a long-term support (LTS) release, so it carries a longer patch window than the interim releases around it. Its most recent patch is 5.0.0, published October 5, 2026.

← Apache Pulsar 4.2 All Apache Pulsar versions
10 / 100
Low Risk
EOL Risk Score™  How is this calculated? →
EOL Recency
0/40
Attack Surface
10/30 Medium tier
CISA KEV Exposure
0/20 Not in KEV
Extended Support
0/10 Available
EOL Risk Score™ — proprietary methodology by endoflife.ai. Factors: EOL recency, attack surface breadth, CISA KEV catalog presence, extended support availability. Updated at every build. Methodology →  ·  View score card →
All Apache Pulsar Versions
VersionLatestEOL DateStatus
2.5 2.5.2 Jan 15, 2021 EOL
2.6 2.6.4 Jun 17, 2021 EOL
2.7 2.7.5 Dec 3, 2021 EOL
2.8 2.8.4 Jun 15, 2022 EOL
2.9 2.9.5 Dec 20, 2022 EOL
2.10 2.10.6 Apr 18, 2023 EOL
2.11 2.11.4 Jan 11, 2024 EOL
3.0 LTS 3.0.17 May 2, 2025 EOL

What does Apache Pulsar 5.0 end of life mean?

When Apache Pulsar 5.0 reaches end of life, the maintainers stop issuing security patches for this version. CVEs discovered after the EOL date are publicly disclosed on the National Vulnerability Database with no patch available. Exploit code frequently appears on GitHub within days of disclosure.

The CVE blind spot: A CVE-based scan does not show the ongoing accumulation of unpatched vulnerabilities in EOL software versions. Some scanners flag unsupported versions of common products, but coverage varies, and none of them give you the date in advance. Running Apache Pulsar 5.0 past its EOL date creates a growing attack surface that a clean scan result does not rule out.

Migrate to Apache Pulsar 5.0 or implement compensating controls — network segmentation, enhanced monitoring, restricted access — while migration is underway.

Frequently Asked Questions
When does Apache Pulsar 5.0 reach end of life?
Apache Pulsar 5.0 reaches end of life on October 5, 2028. That is 725 days remaining.
Is Apache Pulsar 5.0 still supported?
Yes, Apache Pulsar 5.0 is currently supported. The EOL date is October 5, 2028.
What should I upgrade to from Apache Pulsar 5.0?
The recommended upgrade from Apache Pulsar 5.0 is Apache Pulsar 5.0 — the latest actively supported version. Check the Apache Pulsar full timeline for all supported versions.
What are the security risks of running Apache Pulsar 5.0 past EOL?
When Apache Pulsar 5.0 reaches end of life, the maintainers stop issuing security patches. Any CVEs disclosed after the EOL date accumulate with no vendor fix. A CVE-based scan does not show this — it is the CVE blind spot; some scanners flag unsupported versions of common products, but coverage varies and none give the date in advance. Organizations running EOL Apache Pulsar should migrate immediately or implement compensating controls.
Data from endoflife.date API · Generated at build time · How we source data →