Apache Spark 4.0
Apache Spark 4.0
The Apache Spark 4.0 reaches end of service life on Nov 23, 2026. Third-party support keeps it managed past that date — issue management, vulnerability remediation, and compliance maintenance from 24/7 engineers.
24/7 engineers own your Apache Spark 4.0 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- apache-spark
- release
- 4.0
- product Label
- Apache Spark
- release Label
- 4.0
- codename
- lts
- latest Version
- 4.0.4
- release Date
- 2025-05-19
- maintained
- true
- source Url
- https://endoflife.date/apache-spark
Lifecycle Dates
- End of Service Life
- Nov 23, 2026
- Last OEM Support
- Nov 23, 2026
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Apache Spark 4.0 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Apache Spark 4.0?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Apache Spark 4.0 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Apache Spark 4.0 Support: Frequently Asked Questions
Is the Apache Spark 4.0 still supported?
Yes, but Apache Spark support for the Apache Spark 4.0 ends on Nov 23, 2026. You can upgrade on the vendor's schedule, or move to third-party support and keep the release you're on — issues managed, vulnerabilities remediated, compliance maintained.
When is the Apache Spark 4.0 end of service life (EOSL) date?
Apache Spark lists the end of service life for the Apache Spark 4.0 as Nov 23, 2026.
Can I keep using the Apache Spark 4.0 after its EOSL date?
Yes. EOSL means Apache Spark stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Apache Spark 4.0 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Apache Spark 4.0
2 published CVEs affect the Apache Spark 4.0, including 2 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2018-17190 | CRITICAL | 9.8 | Nov 19, 2018 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the master host typically has less outbound access to other resources than a worker, the execution of code on |
| CVE-2025-54920 | HIGH | 8.8 | Mar 16, 2026 | This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs directory to inject malicious JSON payloads that trigger deserialization of arbitrary classes, enabli |