Apache Spark

Apache Spark 3.5 (LTS)

Apache Spark 3.5 (LTS)

Third-party support for the Apache Spark 3.5 (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.

EOSL Date: Nov 30, 2027
Issue Management

24/7 engineers own your Apache Spark 3.5 (LTS) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
apache-spark
release
3.5
product Label
Apache Spark
release Label
3.5 (LTS)
codename
lts
true
latest Version
3.5.9
release Date
2023-09-09
maintained
true
source Url
https://endoflife.date/apache-spark

Lifecycle Dates

End of Service Life
Nov 30, 2027
Last OEM Support
Nov 30, 2027

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Apache Spark 3.5 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Apache Spark 3.5 (LTS)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Apache Spark 3.5 (LTS) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Apache Spark 3.5 (LTS) Support: Frequently Asked Questions

Is the Apache Spark 3.5 (LTS) still supported?

Yes. The Apache Spark 3.5 (LTS) is currently supported by Apache Spark, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.

When is the Apache Spark 3.5 (LTS) end of service life (EOSL) date?

Apache Spark lists the end of service life for the Apache Spark 3.5 (LTS) as Nov 30, 2027.

Can I keep using the Apache Spark 3.5 (LTS) after its EOSL date?

Yes. EOSL means Apache Spark stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Apache Spark 3.5 (LTS) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Apache Spark 3.5 (LTS)

4 published CVEs affect the Apache Spark 3.5 (LTS), including 2 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.

CVESeverityCVSSPublishedSummary
CVE-2018-17190CRITICAL9.8Nov 19, 2018In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the master host typically has less outbound access to other resources than a worker, the execution of code on
CVE-2025-54920HIGH8.8Mar 16, 2026This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs directory to inject malicious JSON payloads that trigger deserialization of arbitrary classes, enabli
CVE-2025-55039MEDIUM6.5Oct 15, 2025This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This vulnerability allows a man-in
CVE-2024-23945MEDIUM5.9Dec 23, 2024Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component accidentally exposes the signed cookie to the end user when there is a mismatch in signature between the current and expected cookie. Exposing the correct cookie signature can lead to further
Get Third Party Support

Related Apache Spark Products

All Apache Spark products →
Apache Spark 3.5 (LTS)
Save 40-70% vs OEM
Get Third Party Support