Openssl 3.x — End of Life

EOL soon
EOL: Nov 1, 2026in 25d7 releases in this series0 CVEs

Openssl 3.x is partially supported: only 3.6, 3.5, 3.4 still receive security fixes, the longest-lived (3.5) until Apr 8, 2030, in 1279 days. The most recent release in this series is 3.6.5. No CVE is currently tracked for Openssl 3.x. The next major version is Openssl 4. See Openssl 4 →

Openssl 3.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
3.6Oct 1, 2025—Nov 1, 20263.6.5EOL soon
3.5LTSApr 8, 2025—Apr 8, 20303.5.9Active
3.4Oct 22, 2024—Oct 22, 20263.4.8EOL soon
3.3Apr 9, 2024—Apr 9, 20263.3.7EOL
3.2Nov 23, 2023—Nov 23, 20253.2.6EOL
3.1Mar 14, 2023—Mar 14, 20253.1.8EOL
3.0LTSSep 7, 2021—Sep 7, 20263.0.22EOL

CVEs affecting Openssl 3.x (0)

No CVEs tracked for Openssl 3.x.

Openssl 3.x will reach end of life — migrate to Openssl 4.x

Openssl 4.x is the next major release. Plan your upgrade before Openssl 3.x stops receiving security patches.

See Openssl 4.x

Add a Openssl 3 EOL badge to your README

Show your users which Openssl version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Openssl 3 EOL status
[![Openssl 3 EOL status](https://eolcanary.com/badge/openssl/3.svg)](https://eolcanary.com/explore/openssl/3)

Frequently asked questions

Is Openssl 3 end of life?

Partially. 4 of the 7 Openssl 3.x releases have reached end of life. Still supported: 3.6, 3.5, 3.4 (until April 8, 2030 at the latest).

What CVEs affect Openssl 3?

No CVEs are currently tracked for Openssl 3.x in the NVD data we monitor.

What is the latest Openssl 3 version?

The latest Openssl 3.x patch release is 3.6.5, released on September 29, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Openssl 3 to Openssl 4?

To migrate from Openssl 3 to Openssl 4: (1) review the official Openssl 4 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Openssl 3 in production?

Only on a supported release (3.6, 3.5, 3.4). Support for Openssl 3.5 ends on April 8, 2030. Make sure you run the latest patch (3.6.5) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA