Apache Log4j 2.3 End of Life
Support dates and upgrade guidance — rebuilt from live data.
End of Life
Apache Log4j 2.3 reached end of life on 20 Sept 2015. It no longer receives security fixes.
3,976 days without security patches
Recommended action: upgrade to Apache Log4j 2. Support timeline
Official dates from the Apache Log4j release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 10 May 2015 | — |
| End of life | 20 Sept 2015 | 10.9 years ago |
| Latest release | 2.3.2 · 29 Dec 2021 | final |
Where to go from 2.3
Recommended target: Apache Log4j 2.
The newest actively supported branch is Apache Log4j 2 (latest release 2.26.1).
Frequently asked questions
Is Apache Log4j 2.3 still safe to use?
Apache Log4j 2.3 reached end of life on 20 Sept 2015, 3,976 days ago, and is no longer covered by standard support. Running it means no guaranteed security fixes.
Can I still download Apache Log4j 2.3?
Yes — the final release (2.3.2) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Apache Log4j 2.3 to?
Upgrade to Apache Log4j 2, the newest actively supported branch.