Apache Spark version lifecycle

tool · Apache Software Foundation

Current status

supported

Supported version lines, end-of-life status, and latest releases for Apache Spark — derived from official vendor sources, not third-party EOL aggregators.

Apache Spark is a unified analytics engine for large-scale data processing with SQL, streaming, machine learning, and graph workloads.

Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.

Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

26

Supported

4

EOL lines

21

Latest stable

4.2.0

2026-07-14

Releases tracked

97

At a glance

Latest release

4.2.0

Line 4.2

Recommended support line

4.2

standard support

Status

STANDARD SUPPORT

Newest supported: 4.2

EOL

Not published

Exact date not officially published

EOL lines include 3.4, 3.3, 3.2, 3.1, 3.0 (+16 more).

Recommended line: 4.2 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

4 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
4.2
standard supportlow
4.2.02026-07-14Not officially publishedlow
4.1
standard supportlow
4.1.32026-07-15Not officially publishedlow
4.0
standard supportlow
4.0.42026-07-15Not officially publishedlow
3.5
standard supportlow
3.5.92026-07-16Not officially publishedlow

End-of-life versions

Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.

Version lineLatest releaseLifecycleEOLRisk
3.43.4.4
end of lifehigh
2023-04-07high
3.33.3.4
end of lifehigh
2022-06-09high
3.23.2.4
end of lifehigh
2021-10-06high
3.13.1.3
end of lifehigh
2021-02-22high
3.03.0.3
end of lifehigh
2020-06-06high
2.42.4.8
end of lifehigh
2018-10-29high
2.32.3.4
end of lifehigh
2018-02-22high
2.22.2.3
end of lifehigh
2017-06-30high
2.12.1.3
end of lifehigh
2016-12-16high
2.02.0.2
end of lifehigh
2016-07-19high
1.61.6.3
end of lifehigh
2015-12-22high
1.51.5.2
end of lifehigh
2015-08-31high
1.41.4.1
end of lifehigh
2015-06-03high
1.31.3.1
end of lifehigh
2015-03-05high
1.21.2.2
end of lifehigh
2014-12-10high
1.11.1.1
end of lifehigh
2014-09-03high
1.01.0.2
end of lifehigh
2014-05-26high
0.90.9.2
end of lifehigh
2014-03-27high
0.70.7.2
end of lifehigh
2013-02-27high
0.60.6.2
end of lifehigh
2012-10-15high
0.50.5.2
end of lifehigh
2012-06-12high

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 4.2standard support
    standard support
  • 4.1standard support
    standard support
  • 4.0standard support
    standard support
  • 3.5standard support
    standard support
  • 3.4end of life · EOL 2023-04-07
    end of life
  • 3.3end of life · EOL 2022-06-09
    end of life
  • 3.2end of life · EOL 2021-10-06
    end of life
  • 3.1end of life · EOL 2021-02-22
    end of life
  • 3.0end of life · EOL 2020-06-06
    end of life
  • 2.4end of life · EOL 2018-10-29
    end of life
  • 2.3end of life · EOL 2018-02-22
    end of life
  • 2.2end of life · EOL 2017-06-30
    end of life
  • 2.1end of life · EOL 2016-12-16
    end of life
  • 2.0end of life · EOL 2016-07-19
    end of life
  • 1.6end of life · EOL 2015-12-22
    end of life
  • 1.5end of life · EOL 2015-08-31
    end of life

Showing 16 of 25 lines with lifecycle periods. See the directory below for the full list.

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2022-33891Known exploited

    Apache Spark Command Injection Vulnerability

    Apache Spark shell command injection vulnerability via Spark UI

    CISA KEV:
    listed · added 2023-03-07 · due 2023-03-28
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    >=3.2.0,<=3.2.1
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
1
Highest CVSS
8.8
  • CVE-2022-33891Known exploited

    Apache Spark Command Injection Vulnerability

    Apache Spark shell command injection vulnerability via Spark UI

    CISA KEV:
    listed · added 2023-03-07 · due 2023-03-28
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    >=3.2.0,<=3.2.1
    Source:
    CISA KEV · Advisory
  • CVE-2025-54920

    Apache Spark: Spark History Server Code Execution Vulnerability

    Affected:
    >=4.0.1-rc1,<3.5.7
    Fixed in:
    3.5.7
    Source:
    OSV source · Advisory
  • CVE-2025-55039

    Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks

    Affected:
    >=3.5.0,<3.5.2
    Fixed in:
    3.5.2
    Source:
    OSV source · Advisory
  • CVE-2023-32007

    Apache Spark: Shell command injection via Spark UI

    Affected:
    >=3.2.0,<=3.2.1
    Source:
    OSV source · Advisory
  • CVE-2023-22946

    Apache Spark proxy-user privilege escalation from malicious configuration class

    Affected:
    <3.4.0
    Fixed in:
    3.4.0
    Source:
    OSV source · Advisory
  • CVE-2022-31777

    Apache Spark XSS vulnerability in log viewer UI Javascript

    Affected:
    >=3.3.0,<3.2.2
    Fixed in:
    3.2.2
    Source:
    OSV source · Advisory
  • CVE-2021-38296
    Affected:
    <3.1.3
    Fixed in:
    3.1.3
    Source:
    OSV source · Advisory
  • CVE-2020-27223
    Affected:
    >=8.8.1,<=8.8.1; >=1.13.0,<=1.13.0; >=11.0.0-NA,<9.4.36; >=3.1.1-NA,<=3.1.1-NA
    Fixed in:
    9.4.36
    Source:
    OSV source · Advisory
  • CVE-2020-27218
    Affected:
    >=11.0.0-beta2,<9.4.35; >=3.0.3,<=3.0.3; >=2.7.0,<=2.7.0
    Fixed in:
    9.4.35
    Source:
    OSV source · Advisory
  • CVE-2020-9480
    Affected:
    <=2.4.5
    Source:
    OSV source · Advisory
  • CVE-2019-20445
    Affected:
    >=2.4.8,<=2.4.8; <4.1.44
    Fixed in:
    4.1.44
    Source:
    OSV source · Advisory
  • CVE-2019-10172
    Affected:
    >=3.0.1,<=3.0.1
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

4.24.14.03.5
Statusstandard supportstandard supportstandard supportstandard support
Latest4.2.04.1.34.0.43.5.9
Released2026-07-142026-07-152026-07-152026-07-16
EOLNot officially publishedNot officially publishedNot officially publishedNot officially published
Risklowlowlowlow

Recent releases

Latest release date 2026-07-14 · 0 in last 30 days · 5 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Apache Spark 4.2 (standard support).

Open upgrade planner →

Upgrade planning

Plan upgrades from Apache Spark version lines that have newer supported options.

Compatibility

Evidence-backed Apache Spark compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Data coverage

Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.

Version lines
26
Concrete releases
97
Supported lines
4
EOL lines
21
Lifecycle coverage
25/26
EOL coverage
21/22
Provenance coverage
25/26

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-02
Latest source update
2026-09-02

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
4.2
standard supportlow
4.2.02026-07-14Not officially published
4.1
standard supportlow
4.1.32026-07-15Not officially published
4.0
standard supportlow
4.0.42026-07-15Not officially published
3.5
standard supportlow
3.5.92026-07-16Not officially published

End of life

Version lineStatusLatest releaseReleasedEOL
3.4
end of lifehigh
3.4.42024-10-212023-04-07
3.3
end of lifehigh
3.3.42023-12-082022-06-09
3.2
end of lifehigh
3.2.42023-04-092021-10-06
3.1
end of lifehigh
3.1.32022-02-062021-02-22
3.0
end of lifehigh
3.0.32021-06-152020-06-06
2.4
end of lifehigh
2.4.82021-05-092018-10-29
2.3
end of lifehigh
2.3.42019-08-252018-02-22
2.2
end of lifehigh
2.2.32019-01-072017-06-30
2.1
end of lifehigh
2.1.32018-06-262016-12-16
2.0
end of lifehigh
2.0.22016-11-072016-07-19
1.6
end of lifehigh
1.6.32016-11-022015-12-22
1.5
end of lifehigh
1.5.22015-11-032015-08-31
1.4
end of lifehigh
1.4.12015-07-082015-06-03
1.3
end of lifehigh
1.3.12015-04-112015-03-05
1.2
end of lifehigh
1.2.22015-04-052014-12-10
1.1
end of lifehigh
1.1.12014-11-192014-09-03
1.0
end of lifehigh
1.0.22014-07-252014-05-26
0.9
end of lifehigh
0.9.22014-07-172014-03-27
0.7
end of lifehigh
0.7.22013-06-022013-02-27
0.6
end of lifehigh
0.6.22013-02-072012-10-15
0.5
end of lifehigh
0.5.22012-11-212012-06-12

Archive / no vendor EOL schedule

Version lineStatusLatest releaseReleasedEOL
4.3
unknownmedium
Not officially published

Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.