Apache Spark version lifecycle
tool · Apache Software Foundation
Current status
Supported version lines, end-of-life status, and latest releases for Apache Spark — derived from official vendor sources, not third-party EOL aggregators.
Apache Spark is a unified analytics engine for large-scale data processing with SQL, streaming, machine learning, and graph workloads.
Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.
Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
26
Supported
4
EOL lines
21
Latest stable
4.2.0
2026-07-14
Releases tracked
97
At a glance
Latest release
4.2.0
Line 4.2
Recommended support line
4.2
standard support
Status
STANDARD SUPPORT
Newest supported: 4.2
EOL
Not published
Exact date not officially published
EOL lines include 3.4, 3.3, 3.2, 3.1, 3.0 (+16 more).
Recommended line: 4.2 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
4 currently supported release lines.
| Version line | Lifecycle | Latest release | Released | EOL | Risk |
|---|---|---|---|---|---|
| 4.2 | standard supportlow | 4.2.0 | 2026-07-14 | Not officially published | low |
| 4.1 | standard supportlow | 4.1.3 | 2026-07-15 | Not officially published | low |
| 4.0 | standard supportlow | 4.0.4 | 2026-07-15 | Not officially published | low |
| 3.5 | standard supportlow | 3.5.9 | 2026-07-16 | Not officially published | low |
End-of-life versions
Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.
| Version line | Latest release | Lifecycle | EOL | Risk |
|---|---|---|---|---|
| 3.4 | 3.4.4 | end of lifehigh | 2023-04-07 | high |
| 3.3 | 3.3.4 | end of lifehigh | 2022-06-09 | high |
| 3.2 | 3.2.4 | end of lifehigh | 2021-10-06 | high |
| 3.1 | 3.1.3 | end of lifehigh | 2021-02-22 | high |
| 3.0 | 3.0.3 | end of lifehigh | 2020-06-06 | high |
| 2.4 | 2.4.8 | end of lifehigh | 2018-10-29 | high |
| 2.3 | 2.3.4 | end of lifehigh | 2018-02-22 | high |
| 2.2 | 2.2.3 | end of lifehigh | 2017-06-30 | high |
| 2.1 | 2.1.3 | end of lifehigh | 2016-12-16 | high |
| 2.0 | 2.0.2 | end of lifehigh | 2016-07-19 | high |
| 1.6 | 1.6.3 | end of lifehigh | 2015-12-22 | high |
| 1.5 | 1.5.2 | end of lifehigh | 2015-08-31 | high |
| 1.4 | 1.4.1 | end of lifehigh | 2015-06-03 | high |
| 1.3 | 1.3.1 | end of lifehigh | 2015-03-05 | high |
| 1.2 | 1.2.2 | end of lifehigh | 2014-12-10 | high |
| 1.1 | 1.1.1 | end of lifehigh | 2014-09-03 | high |
| 1.0 | 1.0.2 | end of lifehigh | 2014-05-26 | high |
| 0.9 | 0.9.2 | end of lifehigh | 2014-03-27 | high |
| 0.7 | 0.7.2 | end of lifehigh | 2013-02-27 | high |
| 0.6 | 0.6.2 | end of lifehigh | 2012-10-15 | high |
| 0.5 | 0.5.2 | end of lifehigh | 2012-06-12 | high |
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 4.2standard supportstandard support
- 4.1standard supportstandard support
- 4.0standard supportstandard support
- 3.5standard supportstandard support
- 3.4end of life · EOL 2023-04-07end of life
- 3.3end of life · EOL 2022-06-09end of life
- 3.2end of life · EOL 2021-10-06end of life
- 3.1end of life · EOL 2021-02-22end of life
- 3.0end of life · EOL 2020-06-06end of life
- 2.4end of life · EOL 2018-10-29end of life
- 2.3end of life · EOL 2018-02-22end of life
- 2.2end of life · EOL 2017-06-30end of life
- 2.1end of life · EOL 2016-12-16end of life
- 2.0end of life · EOL 2016-07-19end of life
- 1.6end of life · EOL 2015-12-22end of life
- 1.5end of life · EOL 2015-08-31end of life
Showing 16 of 25 lines with lifecycle periods. See the directory below for the full list.
Known exploited vulnerabilities
CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.
- CVE-2022-33891Known exploited
Apache Spark Command Injection Vulnerability
Apache Spark shell command injection vulnerability via Spark UI
- CISA KEV:
- listed · added 2023-03-07 · due 2023-03-28
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-78
- Affected:
- >=3.2.0,<=3.2.1
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- Known vulnerabilities
- 12
- Known exploited
- 1
- Highest CVSS
- 8.8
- CVE-2022-33891Known exploited
Apache Spark Command Injection Vulnerability
Apache Spark shell command injection vulnerability via Spark UI
- CISA KEV:
- listed · added 2023-03-07 · due 2023-03-28
- Required action:
- Apply updates per vendor instructions.
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-78
- Affected:
- >=3.2.0,<=3.2.1
- CVE-2025-54920
Apache Spark: Spark History Server Code Execution Vulnerability
- Affected:
- >=4.0.1-rc1,<3.5.7
- Fixed in:
- 3.5.7
- Source:
- OSV source · Advisory
- CVE-2025-55039
Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks
- Affected:
- >=3.5.0,<3.5.2
- Fixed in:
- 3.5.2
- Source:
- OSV source · Advisory
- CVE-2023-32007
Apache Spark: Shell command injection via Spark UI
- Affected:
- >=3.2.0,<=3.2.1
- Source:
- OSV source · Advisory
- CVE-2023-22946
Apache Spark proxy-user privilege escalation from malicious configuration class
- Affected:
- <3.4.0
- Fixed in:
- 3.4.0
- Source:
- OSV source · Advisory
- CVE-2022-31777
Apache Spark XSS vulnerability in log viewer UI Javascript
- Affected:
- >=3.3.0,<3.2.2
- Fixed in:
- 3.2.2
- Source:
- OSV source · Advisory
- CVE-2021-38296
- Affected:
- <3.1.3
- Fixed in:
- 3.1.3
- Source:
- OSV source · Advisory
- CVE-2020-27223
- Affected:
- >=8.8.1,<=8.8.1; >=1.13.0,<=1.13.0; >=11.0.0-NA,<9.4.36; >=3.1.1-NA,<=3.1.1-NA
- Fixed in:
- 9.4.36
- Source:
- OSV source · Advisory
- CVE-2020-27218
- Affected:
- >=11.0.0-beta2,<9.4.35; >=3.0.3,<=3.0.3; >=2.7.0,<=2.7.0
- Fixed in:
- 9.4.35
- Source:
- OSV source · Advisory
- CVE-2020-9480
- Affected:
- <=2.4.5
- Source:
- OSV source · Advisory
- CVE-2019-20445
- Affected:
- >=2.4.8,<=2.4.8; <4.1.44
- Fixed in:
- 4.1.44
- Source:
- OSV source · Advisory
- CVE-2019-10172
- Affected:
- >=3.0.1,<=3.0.1
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2026-07-14 · 0 in last 30 days · 5 in last 90 days
- 2026-07-16
- 2026-07-15
- 2026-07-15
- 2026-07-14
- 2026-06-08
- 2026-05-16
- 2026-02-02
- 2026-01-12
- 2026-01-02
- 2025-12-11
Should I upgrade?
Current versions are supported
The preferred supported release line is Apache Spark 4.2 (standard support).
Upgrade planning
Plan upgrades from Apache Spark version lines that have newer supported options.
Compatibility
Evidence-backed Apache Spark compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.
- ✓Apache Spark 4.2 → Python 3.10
- ✓Apache Spark 4.2 → Python 3.11
- ✓Apache Spark 4.2 → Python 3.12
- ✓Apache Spark 4.2 → Python 3.13
- ✓Apache Spark 4.2 → Python 3.14
- ✓Apache Spark 4.0 → Python 3.10
- ✓Apache Spark 4.0 → Python 3.11
- ✓Apache Spark 4.0 → Python 3.12
- ✓Apache Spark 4.0 → Python 3.13
- ✓Apache Spark 4.0 → Python 3.14
- ✓Apache Spark 4.2 → OpenJDK 21
- ✓Apache Spark 4.2 → OpenJDK 25
Data coverage
Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.
- Version lines
- 26
- Concrete releases
- 97
- Supported lines
- 4
- EOL lines
- 21
- Lifecycle coverage
- 25/26
- EOL coverage
- 21/22
- Provenance coverage
- 25/26
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-09-02
- Latest source update
- 2026-09-02
Sources
First-party and other registered sources contributing release and lifecycle facts.
- Apache Spark Downloadsfirst party · high
Official source: https://spark.apache.org/js/downloads.js
Last verified 2026-09-02
- Apache Spark Runtime Requirementsfirst party
Official source: https://spark.apache.org/docs/latest/index.html
Last checked 2026-09-02
- Apache Spark GitHub Tagsfirst party
Official source: https://github.com/apache/spark/tags
Last checked 2026-09-02
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-09-02
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-09-02
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-09-02
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
End of life
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 3.4 | end of lifehigh | 3.4.4 | 2024-10-21 | 2023-04-07 |
| 3.3 | end of lifehigh | 3.3.4 | 2023-12-08 | 2022-06-09 |
| 3.2 | end of lifehigh | 3.2.4 | 2023-04-09 | 2021-10-06 |
| 3.1 | end of lifehigh | 3.1.3 | 2022-02-06 | 2021-02-22 |
| 3.0 | end of lifehigh | 3.0.3 | 2021-06-15 | 2020-06-06 |
| 2.4 | end of lifehigh | 2.4.8 | 2021-05-09 | 2018-10-29 |
| 2.3 | end of lifehigh | 2.3.4 | 2019-08-25 | 2018-02-22 |
| 2.2 | end of lifehigh | 2.2.3 | 2019-01-07 | 2017-06-30 |
| 2.1 | end of lifehigh | 2.1.3 | 2018-06-26 | 2016-12-16 |
| 2.0 | end of lifehigh | 2.0.2 | 2016-11-07 | 2016-07-19 |
| 1.6 | end of lifehigh | 1.6.3 | 2016-11-02 | 2015-12-22 |
| 1.5 | end of lifehigh | 1.5.2 | 2015-11-03 | 2015-08-31 |
| 1.4 | end of lifehigh | 1.4.1 | 2015-07-08 | 2015-06-03 |
| 1.3 | end of lifehigh | 1.3.1 | 2015-04-11 | 2015-03-05 |
| 1.2 | end of lifehigh | 1.2.2 | 2015-04-05 | 2014-12-10 |
| 1.1 | end of lifehigh | 1.1.1 | 2014-11-19 | 2014-09-03 |
| 1.0 | end of lifehigh | 1.0.2 | 2014-07-25 | 2014-05-26 |
| 0.9 | end of lifehigh | 0.9.2 | 2014-07-17 | 2014-03-27 |
| 0.7 | end of lifehigh | 0.7.2 | 2013-06-02 | 2013-02-27 |
| 0.6 | end of lifehigh | 0.6.2 | 2013-02-07 | 2012-10-15 |
| 0.5 | end of lifehigh | 0.5.2 | 2012-11-21 | 2012-06-12 |
Archive / no vendor EOL schedule
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 4.3 | unknownmedium | — | — | Not officially published |
Apache Spark lifecycle follows spark.apache.org downloads: currently listed release lines are supported. Spark does not publish calendar EOL dates; older lines leave support when no longer on the official downloads page.
