Oracle JDK 11 · Version Status

Oracle JDK 11 End of Life Date

Oracle JDK 11 end-of-life date, support status, and CVE risk. Data reconciled from official vendor documentation and endoflife.date at every build; the source of each date is on the product page.

Oracle JDK 11 is past end of life. Standard support ended September 30, 2023. Patches continue until January 31, 2032 only under Oracle Java SE Subscription, a paid programme — if you are not covered by it, this version is unpatched today.
EOL Date
Sep 30, 2023
1089 days past EOL
Latest Release
11.0.32.1
LTS release
Release Date
Sep 25, 2018
Oracle JDK 11 series
Extended Support
Jan 31, 2032
Oracle Java SE Subscription · paid
Lifecycle detail

Oracle JDK 11 was released on September 25, 2018 and support ended on September 30, 2023 — a supported lifespan of 5 years, in line with the 5 years and 1 month median for Oracle JDK LTS releases. It was a long-term support (LTS) release, so it received a longer patch window than the interim releases around it. Its most recent release is 11.0.32.1, published August 18, 2026. Standard support ended 3 years ago. Security fixes now come only through extended support, published to January 31, 2032; without it this version is unpatched. 6 newer Oracle JDK releases have shipped since.

← Oracle JDK 10 All Oracle JDK versions Oracle JDK 12 →
70 / 100
High Risk
EOL Risk Score™  How is this calculated? →
EOL Recency
40/40
Attack Surface
10/30 Medium tier
CISA KEV Exposure
20/20 Named in CISA KEV
Extended Support
0/10 Available
EOL Risk Score™ — proprietary methodology by endoflife.ai. Factors: EOL recency, attack surface breadth, CISA KEV catalog presence, extended support availability. Updated at every build. Methodology →  ·  View score card →
Recommended upgrade path
Oracle JDK 27
Latest release: 27 · EOL: Mar 31, 2027
View full Oracle JDK timeline →
Extended Support
Extended Oracle JDK 11 support is available

Commercial vendors offer security patches beyond EOL. Compare your options.

Compare Options →
All Oracle JDK Versions
VersionLatestEOL DateStatus
1.0 1.0.2 May 7, 1996 EOL
1.1 1.1.8_010 Oct 9, 2002 EOL
1.2 1.2.2_18 Nov 30, 2003 EOL
1.3 1.3.1_32 Mar 31, 2006 EOL
1.4 1.4.2_42 Oct 30, 2008 EOL
5 5.0u85 Oct 30, 2009 EOL
6 6u211 Dec 31, 2018 EOL
7 LTS 7u351 Jul 31, 2019 EOL

What does Oracle JDK 11 end of life mean?

When Oracle JDK 11 reaches end of life, the maintainers stop issuing security patches for this version. CVEs discovered after the EOL date are publicly disclosed on the National Vulnerability Database with no patch available. Exploit code frequently appears on GitHub within days of disclosure.

The CVE blind spot: A CVE-based scan does not show the ongoing accumulation of unpatched vulnerabilities in EOL software versions. Some scanners flag unsupported versions of common products, but coverage varies, and none of them give you the date in advance. Running Oracle JDK 11 past its EOL date creates a growing attack surface that a clean scan result does not rule out.

Migrate to Oracle JDK 27 or implement compensating controls — network segmentation, enhanced monitoring, restricted access — while migration is underway.

Frequently Asked Questions
When does Oracle JDK 11 reach end of life?
Oracle JDK 11 reached end of life on September 30, 2023. This version is no longer receiving security patches.
Is Oracle JDK 11 still supported?
No. Oracle JDK 11 reached end of life on September 30, 2023 and is no longer receiving security patches.
What should I upgrade to from Oracle JDK 11?
The recommended upgrade from Oracle JDK 11 is Oracle JDK 27 — the latest actively supported version. Check the Oracle JDK full timeline for all supported versions.
What are the security risks of running Oracle JDK 11 past EOL?
When Oracle JDK 11 reaches end of life, the maintainers stop issuing security patches. Any CVEs disclosed after the EOL date accumulate with no vendor fix. A CVE-based scan does not show this — it is the CVE blind spot; some scanners flag unsupported versions of common products, but coverage varies and none give the date in advance. Organizations running EOL Oracle JDK should migrate immediately or implement compensating controls.
Data from endoflife.date API · Generated at build time · How we source data →