Apache Tomcat 9 reaches end of life on 31 March 2027, when support for the 9.0.x branch ends. A new 9.1.x branch will carry Tomcat 9 releases until 31 December 2030. Tomcat 8.5 reached end of life on 31 March 2024, Tomcat 10.0 on 31 October 2022 and Tomcat 7 on 31 March 2021. Tomcat 10.1 and Tomcat 11.0 are supported, and no end of life date has been announced for either. The dates below are from tomcat.apache.org, checked on 9 October 2026.
Apache Tomcat versions and end of life dates
| Tomcat version | Specification | Minimum Java | Status |
|---|---|---|---|
| 11.0.x | Jakarta EE 11 (Servlet 6.1) | 17 | Supported, no EOL date announced (latest 11.0.26) |
| 10.1.x | Jakarta EE 10 (Servlet 6.0) | 11 | Supported, no EOL date announced (latest 10.1.60) |
| 9.0.x | Java EE 8 (Servlet 4.0) | 8 | Support ends 31 March 2027 (latest 9.0.122) |
| 9.1.x | Java EE 8 (Tomcat 9 line) | Not yet published | Starts shortly before 9.0 support ends; releases until 31 December 2030 |
| 10.0.x | Jakarta EE 9 (Servlet 5.0) | 8 | End of life 31 October 2022 (final 10.0.27) |
| 8.5.x | Servlet 3.1 | 7 | End of life 31 March 2024 (final 8.5.100) |
| 8.0.x | Servlet 3.1 | 7 | End of life 30 June 2018 |
| 7.0.x | Servlet 3.0 | 6 | End of life 31 March 2021 |
Source: Which version do I want? on tomcat.apache.org.
Tomcat 9 end of life: what changes on 31 March 2027
The Tomcat team announced the end of support for Tomcat 9.0.x on 11 February 2026. After 31 March 2027, new 9.0.x releases are highly unlikely, bugs that affect only 9.0.x will not be fixed, and security vulnerability reports will not be checked against the 9.0.x branch. Three months later the download links and documentation come down, although every release stays in the Apache archive.
Tomcat 9 gets a longer tail than earlier majors because it is the last version that implements Java EE rather than Jakarta EE. Instead of ending Tomcat 9 outright, the project will start a 9.1.x branch shortly before 9.0.x support ends. The differences are small but they matter for older configurations:
- The APR/native connectors for HTTP, HTTPS and AJP are not available in 9.1.x.
- Tomcat Native 2.0.x stays supported; Tomcat Native 1.3.x does not.
- Teams on APR connectors should move to the NIO connectors now, and to NIO with JSSE or NIO with OpenSSL for HTTPS.
For servers that do not use Tomcat Native, moving from 9.0.x to 9.1.x should be no different from a normal point release. The Tomcat team itself still recommends upgrading to a newer major version rather than settling on 9.1.
Tomcat 8.5 and Tomcat 10.0: already end of life
Tomcat 8.5 support ended on 31 March 2024. The last security fixes listed for it are in 8.5.99, and since then new vulnerability reports are not checked against 8.5 at all. That is the real cost of an EOL Tomcat: nobody tells you whether you are affected. In September 2026, for example, the project fixed CVE-2026-76183, an important-rated bypass of security constraints for WebSocket endpoints that affected every 9.0, 10.1 and 11.0 release up to 9.0.121, 10.1.59 and 11.0.25. Whether 8.5.x or 10.0.x is exposed has not been assessed by the project.
Tomcat 10.0 was a short-lived bridge to Jakarta EE and ended on 31 October 2022, with 10.0.27 as its final release. Anyone still on it should move to 10.1, which keeps the same jakarta.* packages.
Known exploitation is not hypothetical. CVE-2025-24813, a partial PUT flaw in the default servlet that can lead to remote code execution in some configurations, was made public on 10 March 2025, fixed in 9.0.99, 10.1.35 and 11.0.3, and added to CISA's Known Exploited Vulnerabilities catalog on 1 April 2025.
What each major Tomcat upgrade breaks
- Tomcat 9 to 10.x: javax to jakarta. The Servlet, JSP, EL and WebSocket APIs moved from
javax.*tojakarta.*, so applications must be recompiled. Tomcat can convert a Java EE application at deployment if you drop it intowebapps-javaee, and the Tomcat Migration Tool for Jakarta EE does the same conversion ahead of time. - Tomcat 10.1: Java 11 and no APR connector. Tomcat 10.1 requires Java 11 or later, and the APR connector was removed from 10.1.0-M5 onward.
- Tomcat 11: Java 17 and no SecurityManager. Tomcat 11 requires Java 17, removes support for running under a SecurityManager and drops HTTP/2 server push.
- Connector defaults inside Tomcat 9. Since 9.0.31, the release that fixed the Ghostcat AJP flaw CVE-2020-1938, the AJP connector listens on the loopback address and will not start without a
secretunlesssecretRequiredis set to false. Since 9.0.74 the defaultmaxParameterCountdropped from 10,000 to 1,000. Oldserver.xmlfiles carried forward between upgrades are where these surprises hide.
Embedded Tomcat: when Spring Boot reaches end of life, so does Tomcat
Many Tomcat installs are not installs at all. Spring Boot embeds Tomcat inside the application JAR: Spring Boot 2.7 uses Tomcat 9.0, Spring Boot 3.x uses Tomcat 10.1 and Spring Boot 4.x uses Tomcat 11.0. The last public Spring Boot 2.7 release, 2.7.18, manages Tomcat 9.0.83, so an application built on it without an override ships without the CVE-2025-24813 fix and every Tomcat 9 fix after it. Overriding the tomcat.version property works within a major line, but after 31 March 2027 there is no supported 9.0.x left to override to. See Spring Boot end of life for the framework dates.
Your options for an end-of-life Tomcat version
First, find every Tomcat you run. For standalone servers, bin/version.sh prints the exact version. For Spring Boot and other fat-JAR applications, look for tomcat-embed-core in the dependency tree or inside the JAR.
- Stay on your version with OSSeva patches. OSSeva, AceMQ's extended support platform, backports CVE fixes to Apache Tomcat 8.5.x through 10.x: patched builds for 8.5.x and 10.0.x today, and for 9.0.x after Apache support ends on 31 March 2027. Signed builds arrive as Docker images, apt or yum packages, or zip archives, and higher tiers add a connector configuration audit and a 15-minute P1 response SLA. For applications pinned to a Java EE stack or an old JDK, this is the most direct way to stay patched without a forced migration.
- Move to Tomcat 9.1. A reasonable bridge for Tomcat 9 servers that already use NIO connectors, with releases planned through 2030.
- Upgrade to Tomcat 10.1 or 11.0. The long-term answer, budgeted as a Jakarta migration plus a JDK upgrade.
- Use a commercial Spring subscription. Tanzu Spring includes Tomcat binaries alongside Spring and OpenJDK, and AceMQ brokers Tanzu Spring support.
Sources
- Apache Tomcat: Which version do I want?
- End of support for Apache Tomcat 9.0.x, 8.5.x, 10.0.x and 7.0.x announcements
- Tomcat migration guides for 9.0, 10.0, 10.1 and 11.0
- Tomcat security pages for 9, 10, 11 and 8
- CISA Known Exploited Vulnerabilities catalog
Frequently Asked Questions
When is Tomcat 9 end of life?
Support for Apache Tomcat 9.0.x ends on 31 March 2027, as announced by the Tomcat team on 11 February 2026. A new 9.1.x branch will start shortly before that date and receive releases until 31 December 2030.
What is Tomcat 9.1?
Tomcat 9.1.x is the continuation of Tomcat 9 after 9.0.x support ends. It keeps the Java EE 8 APIs but drops the APR/native connectors for HTTP, HTTPS and AJP, and supports only Tomcat Native 2.0.x. Servers that do not use Tomcat Native should be able to move to it like a point release.
Is Tomcat 8.5 end of life?
Yes. Apache Tomcat 8.5 reached end of life on 31 March 2024, and the final release was 8.5.100. New vulnerability reports are no longer checked against 8.5, so the project cannot tell you whether a new CVE affects it.
Is Tomcat 10 end of life?
Tomcat 10.0 reached end of life on 31 October 2022, with 10.0.27 as its final release. Tomcat 10.1 is supported and has no announced end of life date. Users of 10.0 should move to 10.1, which uses the same jakarta.* packages but requires Java 11.
Which Tomcat versions are currently supported?
As of October 2026, Apache Tomcat 11.0, 10.1 and 9.0 are supported. Tomcat 9.0 support ends on 31 March 2027. No end of life date has been announced for 10.1 or 11.0.
Which Java version does each Tomcat version need?
Tomcat 11.0 needs Java 17 or later, Tomcat 10.1 needs Java 11 or later, and Tomcat 9.0 and 10.0 run on Java 8 or later. Tomcat 8.5 required Java 7 or later.
Can I get security patches for Tomcat 8.5 or 9 after end of life?
Yes. OSSeva, AceMQ's extended support platform, backports CVE fixes to Apache Tomcat 8.5.x through 10.x, including patched builds for 9.0.x after Apache support ends on 31 March 2027, delivered as signed Docker images, packages or zip archives.
Go deeper on support and version lifecycles
- ComparisonPostgreSQL vs MySQL: Where They Differ and How to ChooseSee the comparison
- ComparisonOpenSearch vs Elasticsearch: How the Fork Has DivergedSee the comparison
- ComparisonOpen Source and Vendor Support Windows ComparedSee the comparison
- ComparisonMessage Broker Support Options ComparedSee the comparison