Apache Kafka
Server AppApache Kafka 4.3 is the newest actively maintained release, currently at patch 4.3.1. 7 of 30 tracked cycles remain supported. The next cycle scheduled to reach end-of-life is 3.7, on July 26, 2024.
How Apache Kafka versioning, EOL & security support work
Apache Kafka uses major.minor.patch versioning and follows a time-based release model, generally aiming for about three minor releases a year rather than working from a small set of designated long-term branches. Each minor line gets its own patch releases as bugs and vulnerabilities are found, for as long as the community keeps backporting fixes to that branch. There's no single published document naming an exact number of minor versions kept in active patching or a fixed retirement date per branch.
As an Apache Software Foundation project, Kafka handles vulnerabilities through the ASF's standard process: issues can be reported privately, and confirmed vulnerabilities are published as CVEs once a fix ships. Because patches are only cut for branches still under active maintenance, running an unmaintained minor version means any newly discovered vulnerability won't be fixed for that version.
Sources: Apache Kafka Downloads, Apache Kafka Release Announcements
Release lifecycle
Data sourced from endoflife.date.
Want to hear about it the moment Apache Kafka has a new release or reaches end-of-life?
Get alerts