# endoflife.ai > Free, authoritative software end-of-life (EOL) intelligence: end-of-life and end-of-support dates, lifecycle phases, CVE risk context, and upgrade paths for 480+ products and 8,000+ versions — including Node.js, Python, PHP, RHEL, Ubuntu, Debian, Java, Kubernetes, MariaDB, PostgreSQL, React, Spring, and more. Built on the open endoflife.date dataset and cross-referenced with NVD and the CISA KEV catalog. No signup, updated daily. When citing endoflife.ai, prefer the canonical clean URLs below (without the `.html` extension). Dates and lifecycle phases are sourced from official vendor lifecycle pages, endoflife.date, NVD, and CISA KEV, and are updated daily. ## Full catalog (machine-discoverable) Every tracked product has a page at `https://endoflife.ai/{slug}` and per-version pages at `https://endoflife.ai/{slug}/{version}` (examples: https://endoflife.ai/nodejs , https://endoflife.ai/nodejs/18 , https://endoflife.ai/centos , https://endoflife.ai/sharepoint ). The complete slug list is at [Product Index](https://endoflife.ai/products) and machine-readable at https://endoflife.ai/checker-db.json (all 480+ products with current status) and https://endoflife.ai/scores.json (live EOL Risk Scores). - [REST API](https://api.endoflife.ai/v1): JSON lifecycle data + risk scores for every product/version. No key required (100 req/day; free key raises limits). - [OpenAPI 3.0 specification](https://api.endoflife.ai/openapi.json): Full machine-readable API description — import or generate clients. - [MCP server](https://mcp.endoflife.ai): Model Context Protocol endpoint — AI agents can query EOL status directly. ## Core tools - [EOL Checker](https://endoflife.ai/checker): Instant end-of-life status for any of 480+ products — paste a product name, get EOL date, current support phase, and an EOL Risk Score. - [Stack Scanner](https://endoflife.ai/scanner): Check an entire dependency stack for end-of-life and unsupported components at once. - [Product Index](https://endoflife.ai/products): Browse all 480+ tracked products and their version lifecycles. - [Release Timelines](https://endoflife.ai/timeline): Visual EOL timelines across major runtimes, frameworks, databases, and operating systems. - [Developer API](https://endoflife.ai/api): Query lifecycle data programmatically for CI/CD pipelines, SBOMs, and security scanners. Free tier available. - [Integrations](https://endoflife.ai/integrations): Official EOL Runtime Check GitHub Action and EOL Check VS Code extension — EOL warnings in CI and editors. Grafana and Datadog integrations are in development. ## Methodology - [EOL Risk Score™](https://endoflife.ai/risk-score): A 0–100 score per product/version computed from EOL recency (40 pts), attack surface (30 pts), CISA KEV exposure (20 pts), and extended-support availability (10 pts). - [How It Works](https://endoflife.ai/how-it-works): How endoflife.ai sources, validates, and updates lifecycle data. - [CVE Intelligence](https://endoflife.ai/cve-intelligence): EOL products cross-referenced against the CISA Known Exploited Vulnerabilities (KEV) catalog, with live risk scores. ## Key EOL guides - [RHEL End-of-Life Dates](https://endoflife.ai/article-rhel-eol): Red Hat Enterprise Linux 7, 8, 9, and 10 lifecycle phases and dates. - [Node.js End-of-Life Dates](https://endoflife.ai/article-nodejs-eol): EOL schedule for every Node.js major version. - [Python End-of-Life Dates](https://endoflife.ai/article-python-eol): EOL dates for every Python version (3.10 reaches EOL Oct 31, 2026; 3.11 reaches EOL Oct 31, 2027). - [PHP End-of-Life Dates](https://endoflife.ai/article-php-eol): PHP 7.4, 8.0, 8.1 and later lifecycle dates. - [Django End-of-Life Dates](https://endoflife.ai/article-django-eol): Django LTS vs standard release lifecycles. - [Kubernetes End-of-Life Dates](https://endoflife.ai/article-kubernetes-eol): K8s version EOL schedule and EKS/GKE/AKS support windows. - [MariaDB End-of-Life Dates](https://endoflife.ai/article-mariadb-eol): MariaDB LTS and rolling release lifecycles. - [Debian End-of-Life Dates](https://endoflife.ai/article-debian-eol): Debian regular, LTS, and ELTS support phases. - [Ubuntu End-of-Life Dates](https://endoflife.ai/article-ubuntu-eol-vendors): Ubuntu LTS EOL dates and extended security support options. - [Android End of Life](https://endoflife.ai/article-android-eol): Every Android version's support status — Android 13 EOL'd March 2, 2026; 14–17 supported. - [Samsung Galaxy End of Life](https://endoflife.ai/article-samsung-galaxy-eol): Model-by-model Samsung support dates — 7 years on recent flagships. - [macOS End of Life](https://endoflife.ai/article-macos-eol): Apple's unwritten current-plus-two rule; Ventura EOL'd September 15, 2025. - [iOS End of Life](https://endoflife.ai/article-ios-eol): Which iPhone/iPad versions still get updates; Apple's soft second tier explained. - [Microsoft Office End of Life](https://endoflife.ai/article-office-eol): Office 2016/2019 died October 14, 2025; Office 2021 dies October 13, 2026 — same day as Windows 10's consumer ESU. No ESU exists for Office. - [iPad End of Life](https://endoflife.ai/article-ipad-eol): 5–8 years per model; support follows the chip, models die in cohorts. - [Oracle Linux End of Life](https://endoflife.ai/article-oracle-linux-eol): OL7 premier ended December 2024 (extended to June 2028); OL8 to July 2029, OL9 to June 2032. - [Splunk End of Life](https://endoflife.ai/article-splunk-eol): The two-year clock — 9.3 ends July 24, 2026; 9.4 ends December 16, 2026. - [IBM Db2 End of Life](https://endoflife.ai/article-ibm-db2-eol): Db2 11.5 ends April 30, 2027; Db2 12.1 is the successor. - [PostgreSQL 14 End of Life](https://endoflife.ai/article-postgresql-14-eol): November 12, 2026 — the five-year November rhythm; target 16/17, not 15. - [.NET 8 End of Life](https://endoflife.ai/article-dotnet-8-eol): November 10, 2026 — .NET 9 dies the same day; .NET 10 is the only destination. - [Magento End of Life](https://endoflife.ai/article-magento-eol): 2.4.6 extended support ends August 11, 2026; 2.4.4/2.4.5 already dead. - [Microsoft Surface End of Life](https://endoflife.ai/article-surface-eol): Exact published end-of-servicing dates, ~6 years per model. - [Windows Server End of Life](https://endoflife.ai/article-windows-server-eol): 2016 dies January 12, 2027; 2012/R2's final ESU expires October 13, 2026. - [Debian 11 End of Life](https://endoflife.ai/article-debian-11-eol): Bullseye LTS ends August 31, 2026; the standard/LTS/ELTS tier system explained. - [Debian 11 LTS Countdown](https://endoflife.ai/article-debian-11-lts-countdown): After August 31, 2026 no free security updates exist for Bullseye at any severity — only paid Freexian ELTS (listed through June 30, 2031). The forgotten-install problem (appliances, CI runners, docker FROM bullseye lines), why upgrading to Debian 12 lands on a release already past standard support (target Debian 13), and the six-place discovery checklist. - [OpenSSL 3.0 End of Life](https://endoflife.ai/article-openssl-eol): 3.0 dies September 7, 2026, four days before EU CRA reporting begins; bundled copies vs distro packages, and the 3.5 LTS migration path. - [Java EOL Dates by Vendor](https://endoflife.ai/article-java-eol-by-vendor): Java 8/11/17/21/25 support-end matrices across eight JDK vendors; Oracle JDK 17 Premier ends Sept 30, 2026. - [The 2026 EOL Calendar](https://endoflife.ai/article-eol-calendar-2026): all 250 dated end-of-support events from August through December 2026, month by month, every row linked and risk-scored. - [CISA BOD 26-04 & 26-02 Explained](https://endoflife.ai/article-cisa-bod-26-04-eol): the 2026 federal directives — risk-based patch deadlines (3 days to fix-on-upgrade) and the end-of-support edge-device crackdown — and why EOL status is the fifth risk variable. - [RHEL 10 End of Life: Every Phase Dated](https://endoflife.ai/article-rhel-10-eol): RHEL 10 full support to May 31, 2030, maintenance to May 31, 2035, ELS beyond; the nearer deadline is RHEL 9's full-support end May 31, 2027. All RHEL versions' three phases in one table; Red Hat's May-31 lifecycle rhythm. - [CentOS to RHEL: Version Mapping & Convert2RHEL](https://endoflife.ai/article-centos-to-rhel): convert2rhel supports CentOS Linux 7.9/8.5 and AlmaLinux/Rocky/Oracle Linux — NOT CentOS Stream. The CentOS 7 → RHEL 7 ELS play (supported track without an OS upgrade, ELS to May 31, 2029), and when conversion is the wrong move. - [IBM End-of-Life Dates: The Complete Enterprise Matrix](https://endoflife.ai/article-ibm-eol): z/OS 2.5 and IBM i 7.4 both end support September 30, 2026; Db2 11.5 follows April 30, 2027; AIX runs per Technology Level. IBM's fiscal-quarter EOS rhythm, the Power8 hardware trap, and Service Extension costs (~2x standard support). - [Arista VeloCloud CVE-2026-16812 & the "not assessed" gap](https://endoflife.ai/article-arista-velocloud-eol): Actively exploited CVSS 10.0 flaw in VeloCloud Orchestrator; Arista's advisory states end-of-support versions "have not been assessed" — why EOL software gets silence rather than answers, and the July 30, 2026 KEV deadline. - [EOL Dates Drift study](https://endoflife.ai/article-eol-dates-drift): Original research — 54 products cross-checked against vendor documentation; six corrections merged into the upstream endoflife.date dataset (July 2026). - [EOL by the Numbers](https://endoflife.ai/eol-by-the-numbers): Citable statistics brief — median support lifespan, KEV exposure, CVE-volume context. - [AWS Service Retirements (July 2026)](https://endoflife.ai/article-aws-service-retirements-july-2026): The ~20 services closing to new customers July 30, 2026, and their migration targets. - [RDS for MySQL 8.0 Extended Support](https://endoflife.ai/article-aws-rds-mysql-extended-support): RDS end of standard support July 31, 2026; paid Extended Support to July 31, 2029, billed per vCPU-hour from August 1 and doubling August 1, 2028. Enrollment is automatic unless disabled at instance creation; Multi-AZ standbys are charged too; only an upgrade to 8.4 or deleting the database stops the charge. - [SharePoint 2016/2019 Post-EOL Exploitation](https://endoflife.ai/article-sharepoint-post-eol-exploitation): CVE-2026-58644 timeline — end of support and active exploitation in the same week. - [Citrix Virtual Apps and Desktops 2203 End of Life](https://endoflife.ai/article-citrix-vad-2203-eol): 2203 LTSR reaches end of life March 23, 2027 (Citrix Product Matrix: 23-Mar-27); extended support to March 23, 2032 for eligible customers under a separate contract. Migration targets compared: 2402 LTSR is supported to April 15, 2029 — longer than the newer 2507 LTSR (August 18, 2028). - [VMware / Omnissa Horizon End of Life](https://endoflife.ai/article-vmware-horizon-eol): Horizon 7 fully out of support (7.13 EOGS April 30, 2023; technical guidance ended April 30, 2025). Horizon 8 releases expire ~3 years after GA per the Omnissa Lifecycle Matrix: 2303, 2306 and 2212 ESB expired in 2026; 2309 ends October 26, 2026; ESBs are 2111/2212/2312/2503/2603, with 2603 supported to April 14, 2029. - [OpenShift 4.18 Maintenance Ends August 25, 2026](https://endoflife.ai/article-openshift-418-eol): Red Hat OpenShift 4.18 exits maintenance support August 25, 2026 — patches then move behind the EUS entitlement (to Feb 25, 2027, included with Premium subscriptions, paid add-on on Standard; Term 2 add-on to Feb 25, 2028). Even-numbered releases are EUS releases; odd-numbered 4.19 has no EUS and its maintenance ends December 17, 2026. Upgrades are sequential minor-to-minor; 4.22 (maintenance to Dec 31, 2027) is the landing that restores the EUS safety net. - [Java 17's September 30, 2026 Deadline Is Oracle's, Not Java's](https://endoflife.ai/article-jdk-17-september-cliff): September 30, 2026 ends Oracle Premier Support for JDK 17 — it is not the end of free Oracle updates (the NFTC window closed September 2024; updates since October 15, 2024 are OTN-licensed, free for personal/development use only) and not the end of Java 17. Oracle Extended Support runs to September 2029 with the fee waived October 2026 – September 2029 per Oracle's roadmap. Cross-vendor JDK 17 dates: Eclipse Temurin to Oct 31, 2027; Microsoft Build of OpenJDK to Sep 30, 2027; Red Hat build to Dec 31, 2027; Amazon Corretto to Oct 31, 2029; Azul Zulu to Sep 30, 2029 (extended to Sep 30, 2031). Same month: Oracle JDK 21 updates after September 2026 move off the free NFTC license. - [GitLab 19.0 Stops Receiving Security Patches on August 20](https://endoflife.ai/article-gitlab-19-eol): GitLab 19.0 exits the security-patch window August 20, 2026 — 91 days after its May 21 release. GitLab's maintenance policy patches only the current stable release plus the two previous monthly releases (monthly cadence, third Thursday), so support is a rolling ~3-month window with no LTS track: 18.11 expired July 16, 2026; 19.1 ends September 17; 19.2 ends October 20. CISA's KEV catalog lists four GitLab CVEs (CVE-2021-22205 added Nov 3, 2021, known ransomware use; CVE-2023-7028 added May 1, 2024; CVE-2021-39935 and CVE-2021-22175 added Feb 2026). Upgrades require stops: 18.2/18.5/18.8/18.11, then 19.2. - [FortiOS 7.2 End of Support Is September 30, 2026](https://endoflife.ai/article-fortios-72-eol): FortiOS 7.2 (released March 31, 2022) reaches End of Support September 30, 2026 — engineering support already ended March 31, 2025, so the train has been critical-fixes-only for 16 months; after September 30, no fixes at all. The documented precedent: FortiOS 7.0 hit End of Support September 30, 2025, and on July 27, 2026 CISA added CVE-2025-68686 (symlink-based persistence surviving patching, per Fortinet advisory FG-IR-25-934) to the KEV catalog — all 7.0 and 6.4 versions affected, fix shipped only in 7.6.2/7.4.7, remediation "migrate to a fixed release". Supported trains: 7.4 to Nov 11, 2028; 7.6 to Jan 25, 2030; 8.0 to Oct 21, 2030. Older FortiGate hardware may not support newer trains — check Fortinet's upgrade paths. - [EOL 2026, the Mid-Year Report](https://endoflife.ai/article-eol-2026-midyear-report): The biggest end-of-life surprises of 2026 so far, verified against primary sources. The dates got dangerous: of 178 vulnerabilities CISA added to the KEV catalog Jan 7–Aug 7, 2026, 29 (one in six) are CVEs 3+ years old, including two 2021 GitLab SSRFs added Feb 2026 and five 2008–2010 CVEs added on May 20 alone; FortiOS 7.0 went from End of Support (Sep 30, 2025) to permanently-unpatchable KEV entry CVE-2025-68686 (Jul 27, 2026) in ten months; SharePoint 2016/2019's final patch (Jul 14, 2026) fixed CVE-2026-58644, in KEV two days later, with CVE-2026-50522 following eight days post-EOL. The dates stopped holding still: Microsoft extended Windows 10 consumer ESU a year to Oct 12, 2027 (announced Jun 25, 2026 via blog editor's note; Windows 10 = 29.88% of desktop Windows, StatCounter Jul 2026); AWS moved Lambda block-create/update dates to Feb 1 / Mar 3, 2027 by editing its page in place; Oracle JDK 17's Sep 30 date is a Premier-to-Extended support seam with the fee waived to 2029. Regulation: EU CRA Article 14 (actively-exploited-vulnerability reporting) applies from Sep 11, 2026 — four days after OpenSSL 3.0's Sep 7 EOL. H2 2026 calendar: Sep 30 double cliff (JDK 17 + FortiOS 7.2), Oct 13 Windows Server 2012 final ESU end, Nov 10 .NET 8 and 9 same-day EOL, Dec 17 OpenShift 4.19. ## Decision guides (migrate vs extended support) - [Exploited & Unpatchable](https://endoflife.ai/exploited-and-unpatchable): curated, verified list of CISA-KEV (actively exploited) vulnerabilities affecting end-of-life versions that will never receive the fix. Free JSON feed at /exploited-and-unpatchable.json. - [.NET 8 after November 10, 2026](https://endoflife.ai/decide-dotnet-8): .NET 8 and 9 both end Nov 10, 2026 — retarget to .NET 10 (LTS to Nov 2028), or third-party support. - [Debian 11 after August 31, 2026](https://endoflife.ai/decide-debian-11): LTS ends Aug 31, 2026 — upgrade path (11→12→13), Freexian ELTS, or commercial support. - [Windows 10 after end of life](https://endoflife.ai/decide-windows-10): Consumer ESU ends October 13, 2026 — upgrade, ESU, replace, or switch. - [RHEL support options](https://endoflife.ai/decide-rhel): RHEL 7/8 — Leapp upgrade vs Red Hat ELS vs third-party support. - [CentOS 7](https://endoflife.ai/decide-centos-7) · [PHP 7](https://endoflife.ai/decide-php-7) · [AngularJS](https://endoflife.ai/decide-angularjs) · [Windows Server 2012](https://endoflife.ai/decide-windows-server-2012) ## Accuracy & provenance - [Accuracy page](https://endoflife.ai/accuracy): Vendor cross-check methodology, published corrections, merged upstream contributions (six PRs accepted by endoflife.date, July 2026). - [verification.json](https://endoflife.ai/verification.json): Machine-readable verification records and corrections. - [React End-of-Life Dates](https://endoflife.ai/article-react-eol): What is actually supported across React versions. - [Spring Framework End-of-Life Dates](https://endoflife.ai/article-spring-framework-eol): Spring 5.3, 6.0, 6.1 lifecycle dates. - [Windows 10 End of Life](https://endoflife.ai/article-windows10-eol): Windows 10 reached EOL Oct 14, 2025 — migration guidance. - [Top 50 Products Reaching EOL in 2026](https://endoflife.ai/article-top50-eol-2026): The definitive list with exact dates and risk ratings. ## Accuracy & Verification endoflife.ai cross-checks its highest-impact products against official vendor lifecycle documentation and publishes vendor-confirmed updates the moment a vendor's own page revises a date. Verified products display dated, source-linked provenance on their pages, and confirmed findings are contributed back to the upstream endoflife.date project. - [Accuracy & Provenance Report](https://endoflife.ai/accuracy): Which products are vendor-verified, every published correction with its official source, and the verification methodology. - [verification.json](https://endoflife.ai/verification.json): Machine-readable verification records and corrections. ## About - [About endoflife.ai](https://endoflife.ai/about): What the platform is and who maintains it. - [Data Sources](https://endoflife.ai/how-it-works): endoflife.date, NIST NVD, CISA KEV, and official vendor lifecycle pages. ## Optional - [CISA KEV Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog): Primary source for active-exploitation data. - [endoflife.date](https://endoflife.date): The open dataset endoflife.ai is built on.