Hbase 2.x — End of Life

Active
5 releases in this series0 CVEs

Hbase 2.x is partially supported: only 2.6, 2.5 still receive security fixes. The most recent release in this series is 2.6.7. No CVE is currently tracked for Hbase 2.x. The next major version is Hbase 3. See Hbase 3 →

Hbase 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.6May 17, 2024—No2.6.7Active
2.5Aug 31, 2022—No2.5.16Active
2.4Dec 15, 2020—May 25, 20252.4.18EOL
2.3Jul 13, 2020—Oct 19, 20212.3.7EOL
2.2Jul 25, 2019—Apr 19, 20212.2.7EOL

CVEs affecting Hbase 2.x (0)

No CVEs tracked for Hbase 2.x.

Hbase 2.x will reach end of life — migrate to Hbase 3.x

Hbase 3.x is the next major release. Plan your upgrade before Hbase 2.x stops receiving security patches.

See Hbase 3.x

Add a Hbase 2 EOL badge to your README

Show your users which Hbase version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Hbase 2 EOL status
[![Hbase 2 EOL status](https://eolcanary.com/badge/hbase/2.svg)](https://eolcanary.com/explore/hbase/2)

Frequently asked questions

Is Hbase 2 end of life?

Partially. 3 of the 5 Hbase 2.x releases have reached end of life. Still supported: 2.6, 2.5.

What CVEs affect Hbase 2?

No CVEs are currently tracked for Hbase 2.x in the NVD data we monitor.

What is the latest Hbase 2 version?

The latest Hbase 2.x patch release is 2.6.7, released on October 1, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Hbase 2 to Hbase 3?

To migrate from Hbase 2 to Hbase 3: (1) review the official Hbase 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Hbase 2 in production?

Only on a supported release (2.6, 2.5). Make sure you run the latest patch (2.6.7) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA