JSON-java (org.json) 20260522 · Version Status

JSON-java (org.json) 20260522 End of Life Date

JSON-java (org.json) 20260522 end-of-life date, support status, and CVE risk. Data from endoflife.date and official vendor documentation.

JSON-java (org.json) 20260522 is past end of life. This version no longer receives security patches. 13 days past EOL — migrate to a supported version immediately.
EOL Date
Jul 19, 2026
13 days past EOL
Latest Release
20260522
Standard release
Release Date
May 22, 2026
JSON-java (org.json) 20260522 series
Lifecycle detail

JSON-java (org.json) 20260522 was released on May 22, 2026 and support ended on July 19, 2026 — a supported lifespan of 2 months, shorter than the 5 months median for JSON-java (org.json) releases. The last patch it will ever receive is 20260522, published May 22, 2026 — 2 months before support ended. It has been without security patches for 13 days.

← JSON-java (org.json) 20251224 All JSON-java (org.json) versions JSON-java (org.json) 20260719 →
35 / 100
Medium Risk
EOL Risk Score™  How is this calculated? →
EOL Recency
25/40
Attack Surface
10/30 Medium tier
CISA KEV Exposure
0/20 Not in KEV
Extended Support
0/10 Available
EOL Risk Score™ — proprietary methodology by endoflife.ai. Factors: EOL recency, attack surface breadth, CISA KEV catalog presence, extended support availability. Updated at every build. Methodology →  ·  View score card →
Recommended upgrade path
JSON-java (org.json) 20260719
Latest release: 20260719 · EOL: Supported
View full JSON-java (org.json) timeline →
Extended Support
Extended JSON-java (org.json) 20260522 support is available

Commercial vendors offer security patches beyond EOL. Compare your options.

Compare Options →
All JSON-java (org.json) Versions
VersionLatestEOL DateStatus
20220320 20220320 Feb 27, 2023 EOL
20230227 20230227 Jun 18, 2023 EOL
20230618 20230618 Oct 13, 2023 EOL
20231013 20231013 Mar 3, 2024 EOL
20240303 20240303 Dec 24, 2024 EOL
20241224 20241224 Jan 7, 2025 EOL
20250107 20250107 May 17, 2025 EOL
20250517 20250517 Dec 24, 2025 EOL

What does JSON-java (org.json) 20260522 end of life mean?

When JSON-java (org.json) 20260522 reaches end of life, the maintainers stop issuing security patches for this version. CVEs discovered after the EOL date are publicly disclosed on the National Vulnerability Database with no patch available. Exploit code frequently appears on GitHub within days of disclosure.

The CVE blind spot: Most vulnerability scanners check for known CVEs but do not flag the ongoing accumulation of unpatched vulnerabilities in EOL software versions. Running JSON-java (org.json) 20260522 past its EOL date creates a permanently growing attack surface that standard security tooling will not surface.

Migrate to JSON-java (org.json) 20260719 or implement compensating controls — network segmentation, enhanced monitoring, restricted access — while migration is underway.

Frequently Asked Questions
When does JSON-java (org.json) 20260522 reach end of life?
JSON-java (org.json) 20260522 reached end of life on July 19, 2026. This version is no longer receiving security patches.
Is JSON-java (org.json) 20260522 still supported?
No. JSON-java (org.json) 20260522 reached end of life on July 19, 2026 and is no longer receiving security patches.
What should I upgrade to from JSON-java (org.json) 20260522?
The recommended upgrade from JSON-java (org.json) 20260522 is JSON-java (org.json) 20260719 — the latest actively supported version. Check the JSON-java (org.json) full timeline for all supported versions.
What are the security risks of running JSON-java (org.json) 20260522 past EOL?
When JSON-java (org.json) 20260522 reaches end of life, the maintainers stop issuing security patches. Any CVEs disclosed after the EOL date accumulate with no remediation path. Most vulnerability scanners do not flag this — it is the CVE blind spot. Organizations running EOL JSON-java (org.json) should migrate immediately or implement compensating controls.
Data from endoflife.date API · Generated at build time · How we source data →