AWS Lambda Custom Runtime (AL2) · Version Status

AWS Lambda Custom Runtime (AL2) End of Life Date

AWS Lambda Custom Runtime (AL2) end-of-life date, support status, and CVE risk. Data reconciled from official vendor documentation and endoflife.date at every build; the source of each date is on the product page.

AWS Lambda Custom Runtime (AL2) reaches end of life on March 3, 2027. Plan your migration now — 172 days remaining.
📅 Get reminded before AWS Lambda Custom Runtime (AL2) reaches EOL on March 3, 2027 — alerts 90, 30 & 7 days out.
Google →
✉️ Or get it by email — alerts at 90 / 60 / 30 / 7 days and on the day: Free · one-click unsubscribe in every email · no other mail, ever
EOL Date
Mar 3, 2027
172 days remaining
Latest Release
Standard release
Release Date
Aug 12, 2020
AWS Lambda Custom Runtime (AL2) series
Lifecycle detail

AWS Lambda provided.al2 was released on August 12, 2020 and support is scheduled to end on March 3, 2027 — a planned supported lifespan of 6 years and 7 months, longer than the 3 years and 10 months median for AWS Lambda releases.

← AWS Lambda Java 8 (AL2) All AWS Lambda versions AWS Lambda .NET 5 (container-only) →
18 / 100
Low Risk
EOL Risk Score™  How is this calculated? →
EOL Recency
8/40
Attack Surface
10/30 Medium tier
CISA KEV Exposure
0/20 Not in KEV
Extended Support
0/10 Available
EOL Risk Score™ — proprietary methodology by endoflife.ai. Factors: EOL recency, attack surface breadth, CISA KEV catalog presence, extended support availability. Updated at every build. Methodology →  ·  View score card →
Recommended upgrade path
AWS Lambda Java 17 (AL2023)
Latest release: — · EOL: Aug 31, 2029
View full AWS Lambda timeline →
Extended Support
Extended AWS Lambda Custom Runtime (AL2) support is available

Commercial vendors offer security patches beyond EOL. Compare your options.

Compare Options →
All AWS Lambda Versions
VersionLatestEOL DateStatus
Node.js 0.10 Oct 31, 2016 EOL
Java 8 (AL1) Mar 3, 2027 Warning
Python 2.7 May 30, 2022 EOL
Node.js 4.3 Mar 5, 2020 EOL
.NET Core 1.0 Jul 30, 2019 EOL
Node.js 6.10 Aug 12, 2019 EOL
Python 3.6 Aug 29, 2022 EOL
Node.js 4.3 edge Apr 30, 2019 EOL

What does AWS Lambda Custom Runtime (AL2) end of life mean?

When AWS Lambda Custom Runtime (AL2) reaches end of life, the maintainers stop issuing security patches for this version. CVEs discovered after the EOL date are publicly disclosed on the National Vulnerability Database with no patch available. Exploit code frequently appears on GitHub within days of disclosure.

The CVE blind spot: Most vulnerability scanners check for known CVEs but do not flag the ongoing accumulation of unpatched vulnerabilities in EOL software versions. Running AWS Lambda Custom Runtime (AL2) past its EOL date creates a permanently growing attack surface that standard security tooling will not surface.

Migrate to AWS Lambda Java 17 (AL2023) or implement compensating controls — network segmentation, enhanced monitoring, restricted access — while migration is underway.

Frequently Asked Questions
When does AWS Lambda Custom Runtime (AL2) reach end of life?
AWS Lambda Custom Runtime (AL2) reached end of life on March 3, 2027. That is 172 days remaining.
Is AWS Lambda Custom Runtime (AL2) still supported?
AWS Lambda Custom Runtime (AL2) is still supported but approaching end of life on March 3, 2027. Begin planning your migration now.
What should I upgrade to from AWS Lambda Custom Runtime (AL2)?
The recommended upgrade from AWS Lambda Custom Runtime (AL2) is AWS Lambda Java 17 (AL2023) — the latest actively supported version. Check the AWS Lambda full timeline for all supported versions.
What are the security risks of running AWS Lambda Custom Runtime (AL2) past EOL?
When AWS Lambda Custom Runtime (AL2) reaches end of life, the maintainers stop issuing security patches. Any CVEs disclosed after the EOL date accumulate with no remediation path. Most vulnerability scanners do not flag this — it is the CVE blind spot. Organizations running EOL AWS Lambda should migrate immediately or implement compensating controls.
Data from endoflife.date API · Generated at build time · How we source data →