Apache Cassandra version lifecycle

database · Apache Software Foundation

Current status

supported

Supported version lines, end-of-life status, and latest releases for Apache Cassandra — derived from official vendor sources, not third-party EOL aggregators.

Apache Cassandra is a distributed NoSQL database designed for high availability, linear scalability, and fault tolerance across commodity hardware.

Lifecycle for Apache Cassandra follows the official download page: roughly the latest three minor lines remain available/supported. Cassandra does not publish calendar EOL dates; older lines leave the supported window when newer GA lines ship.

Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

19

Supported

3

EOL lines

15

Latest stable

5.0.9

2026-08-07

Releases tracked

247

At a glance

Latest release

5.0.9

Line 5.0

Recommended support line

5.0

standard support

Status

STANDARD SUPPORT

Newest supported: 5.0

EOL

Not published

Exact date not officially published

EOL lines include 3.11, 3.2, 3.1, 3.0, 2.2 (+10 more).

Recommended line: 5.0 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

3 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
5.0
standard supportlow
5.0.92026-08-07Not officially publishedlow
4.1
standard supportlow
4.1.122026-08-07Not officially publishedlow
4.0
standard supportlow
4.0.212026-08-07Not officially publishedlow

End-of-life versions

Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.

Version lineLatest releaseLifecycleEOLRisk
3.113.11.19
end of lifehigh
2024-08-29high
3.23.2.1
end of lifehigh
2022-12-07high
3.13.1.1
end of lifehigh
2021-07-22high
3.03.0.32
end of lifehigh
2017-06-19high
2.22.2.19
end of lifehigh
2016-01-14high
2.12.1.22
end of lifehigh
2015-12-14high
2.02.0.17
end of lifehigh
2015-11-06high
1.21.2.19
end of lifehigh
2015-07-17high
1.11.1.12
end of lifehigh
2014-09-07high
1.01.0.12
end of lifehigh
2013-08-28high
0.80.8.10
end of lifehigh
2012-12-29high
0.70.7.10
end of lifehigh
2012-04-20high
0.60.6.13
end of lifehigh
2011-10-18high
0.50.5.1
end of lifehigh
2011-06-02high
0.40.4.2
end of lifehigh
2011-01-10high

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 5.0standard support
    standard support
  • 4.1standard support
    standard support
  • 4.0standard support
    standard support
  • 3.11end of life · EOL 2024-08-29
    standard supportend of life
  • 3.2end of life · EOL 2022-12-07
    standard supportend of life
  • 3.1end of life · EOL 2021-07-22
    standard supportend of life
  • 3.0end of life · EOL 2017-06-19
    standard supportend of life
  • 2.2end of life · EOL 2016-01-14
    standard supportend of life
  • 2.1end of life · EOL 2015-12-14
    standard supportend of life
  • 2.0end of life · EOL 2015-11-06
    standard supportend of life
  • 1.2end of life · EOL 2015-07-17
    standard supportend of life
  • 1.1end of life · EOL 2014-09-07
    standard supportend of life
  • 1.0end of life · EOL 2013-08-28
    standard supportend of life
  • 0.8end of life · EOL 2012-12-29
    standard supportend of life
  • 0.7end of life · EOL 2012-04-20
    standard supportend of life
  • 0.6end of life · EOL 2011-10-18
    standard supportend of life

Showing 16 of 18 lines with lifecycle periods. See the directory below for the full list.

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2016-3427Known exploited

    Oracle Java SE and JRockit Unspecified Vulnerability

    CISA KEV:
    listed · added 2023-05-12 · due 2023-06-02
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-284
    Affected:
    >=3.11.0,<3.11.8
    Fixed in:
    3.11.8
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
1
Highest CVSS
9.8
  • CVE-2016-3427Known exploited

    Oracle Java SE and JRockit Unspecified Vulnerability

    CISA KEV:
    listed · added 2023-05-12 · due 2023-06-02
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-284
    Affected:
    >=3.11.0,<3.11.8
    Fixed in:
    3.11.8
    Source:
    CISA KEV · Advisory
  • CVE-2026-32588GHSA-qffm-gf3j-6mvg

    Apache Cassandra has an authenticated DoS over CQL

    Affected:
    >=4.0,<4.0.20; >=5.0,<5.0.7; >=4.1,<4.1.11
    Fixed in:
    4.0.20, 5.0.7, 4.1.11
    Source:
    OSV source · Advisory
  • CVE-2026-27314GHSA-qxpc-96fq-wwmg

    Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator

    Affected:
    >=5.0-alpha1,<5.0.7
    Fixed in:
    5.0.7
    Source:
    OSV source · Advisory
  • CVE-2026-27315GHSA-fh34-c629-p8xj

    Apache Cassandra has sensitive Information Leak in cqlsh

    Affected:
    >=4.0,<4.0.20
    Fixed in:
    4.0.20
    Source:
    OSV source · Advisory
  • CVE-2026-32588

    Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing

    Affected:
    >=5.0.0,<5.0.7
    Fixed in:
    5.0.7
    Source:
    OSV source · Advisory
  • CVE-2026-27315

    Apache Cassandra: cqlsh history sensitive information leak

    Affected:
    >=4.0.0,<4.0.20
    Fixed in:
    4.0.20
    Source:
    OSV source · Advisory
  • CVE-2026-27314

    Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass

    Affected:
    >=5.0.0,<5.0.7
    Fixed in:
    5.0.7
    Source:
    OSV source · Advisory
  • CVE-2025-26467GHSA-5c4f-pxmx-xcm4

    Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

    Affected:
    >=4.0.16,<4.0.17
    Fixed in:
    4.0.17
    Source:
    OSV source · Advisory
  • CVE-2025-26467

    Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

    Affected:
    >=5.0.0,<5.0.3
    Fixed in:
    5.0.3
    Source:
    OSV source · Advisory
  • CVE-2025-24860GHSA-3cjf-fwcq-xh22

    Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions

    Affected:
    >=4.1-alpha1,<4.1.8; >=4.0-alpha1,<4.0.16; >=5.0-alpha1,<5.0.3
    Fixed in:
    4.1.8, 4.0.16, 5.0.3
    Source:
    OSV source · Advisory
  • CVE-2024-27137GHSA-rgfx-7p65-3ff4

    Apache Cassandra: unrestricted deserialization of JMX authentication credentials

    Affected:
    >=5.0-beta1,<5.0.3; >=4.1.0,<4.1.8; >=4.0.2,<4.0.15
    Fixed in:
    5.0.3, 4.1.8, 4.0.15
    Source:
    OSV source · Advisory
  • CVE-2025-23015GHSA-wmcc-9vch-jmx4

    Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions

    Affected:
    >=5.0-alpha1,<5.0.3; >=4.1-alpha1,<4.1.8; >=4.0-alpha1,<4.0.16; >=3.1,<3.11.18; <3.0.31
    Fixed in:
    5.0.3, 4.1.8, 4.0.16, 3.11.18, 3.0.31
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

5.04.14.0
Statusstandard supportstandard supportstandard support
Latest5.0.94.1.124.0.21
Released2026-08-072026-08-072026-08-07
EOLNot officially publishedNot officially publishedNot officially published
Risklowlowlow

Recent releases

Latest release date 2026-08-07 · 3 in last 30 days · 3 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Apache Cassandra 5.0 (standard support).

Open upgrade planner →

Upgrade planning

Plan upgrades from Apache Cassandra version lines that have newer supported options.

Compatibility

Evidence-backed Apache Cassandra compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Data coverage

Lifecycle for Apache Cassandra follows the official download page: roughly the latest three minor lines remain available/supported. Cassandra does not publish calendar EOL dates; older lines leave the supported window when newer GA lines ship.

Version lines
19
Concrete releases
247
Supported lines
3
EOL lines
15
Lifecycle coverage
18/19
EOL coverage
15/16
Provenance coverage
18/19

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-02
Latest source update
2026-09-02

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
5.0
standard supportlow
5.0.92026-08-07Not officially published
4.1
standard supportlow
4.1.122026-08-07Not officially published
4.0
standard supportlow
4.0.212026-08-07Not officially published

End of life

Version lineStatusLatest releaseReleasedEOL
3.11
end of lifehigh
3.11.192025-02-062024-08-29
3.2
end of lifehigh
3.2.12016-01-142022-12-07
3.1
end of lifehigh
3.1.12015-12-142021-07-22
3.0
end of lifehigh
3.0.322025-02-062017-06-19
2.2
end of lifehigh
2.2.192020-10-292016-01-14
2.1
end of lifehigh
2.1.222020-08-282015-12-14
2.0
end of lifehigh
2.0.172015-09-182015-11-06
1.2
end of lifehigh
1.2.192014-09-122015-07-17
1.1
end of lifehigh
1.1.122013-05-222014-09-07
1.0
end of lifehigh
1.0.122012-09-242013-08-28
0.8
end of lifehigh
0.8.102012-02-082012-12-29
0.7
end of lifehigh
0.7.102011-10-312012-04-20
0.6
end of lifehigh
0.6.132011-04-182011-10-18
0.5
end of lifehigh
0.5.12010-03-132011-06-02
0.4
end of lifehigh
0.4.22010-03-132011-01-10

Archive / no vendor EOL schedule

Version lineStatusLatest releaseReleasedEOL
0.3
unknownmedium
Not officially published

Lifecycle for Apache Cassandra follows the official download page: roughly the latest three minor lines remain available/supported. Cassandra does not publish calendar EOL dates; older lines leave the supported window when newer GA lines ship.