Proxmox VE 8
Proxmox VE 8
The Proxmox VE 8 reaches end of service life on Aug 31, 2026. Third-party support keeps it managed past that date — issue management, vulnerability remediation, and compliance maintenance from 24/7 engineers.
24/7 engineers own your Proxmox VE 8 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- proxmox-ve
- release
- 8
- product Label
- Proxmox VE
- release Label
- 8
- codename
- lts
- latest Version
- 8.4
- release Date
- 2023-06-22
- maintained
- true
- source Url
- https://endoflife.date/proxmox-ve
Lifecycle Dates
- End of Service Life
- Aug 31, 2026
- Last OEM Support
- Aug 31, 2026
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Proxmox VE 8 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Proxmox VE 8?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Proxmox VE 8 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Proxmox VE 8 Support: Frequently Asked Questions
Is the Proxmox VE 8 still supported?
Yes, but Proxmox VE support for the Proxmox VE 8 ends on Aug 31, 2026. You can upgrade on the vendor's schedule, or move to third-party support and keep the release you're on — issues managed, vulnerabilities remediated, compliance maintained.
When is the Proxmox VE 8 end of service life (EOSL) date?
Proxmox VE lists the end of service life for the Proxmox VE 8 as Aug 31, 2026.
Can I keep using the Proxmox VE 8 after its EOSL date?
Yes. EOSL means Proxmox VE stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Proxmox VE 8 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Proxmox VE 8
6 published CVEs affect the Proxmox VE 8, including 3 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-35508 | CRITICAL | 9.8 | Dec 4, 2022 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions an |
| CVE-2023-43320 | HIGH | 8.8 | Sep 27, 2023 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. |
| CVE-2022-35507 | HIGH | 7.1 | Dec 4, 2022 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3. |
| CVE-2025-57540 | MEDIUM | 5.4 | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks. |
| CVE-2025-57539 | MEDIUM | 5.4 | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session hijacking or other attacks. |
| CVE-2025-57538 | MEDIUM | 5.4 | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected configuration page. This can lead to arbitrary JavaScript execution. |