end-of-life.org

Ruby 3.1 End of Life

Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.

End of Life

Ruby 3.1 reached end of life on 26 Mar 2025. It no longer receives security fixes.

501 days without security patches
1 Ruby CVEs published since EOL
Recommended action: upgrade to Ruby 4.0.
Check your versionruby --version

Support timeline

Official dates from the Ruby release process.

MilestoneDateStatus
Initial release25 Dec 2021
End of life 26 Mar 2025 1.4 years ago
Latest release3.1.7 · 26 Mar 2025 final

The cost of staying: CVEs since end of life

1 Ruby vulnerabilities have been published since 26 Mar 2025. All were fixed in supported branches — 3.1 received none of them. Source: NVD.

Ruby CVEs published since 3.1's EOL, by year

0 of the 1 are rated critical · data refreshed 2026-08-09

0 2.5 5 1 2026
CVE-2026-46727 CVSS 8.1

Published 22 May 2026 · rated high — fixed in supported branches only, never in 3.1. Details

Where to go from 3.1

Recommended target: Ruby 4.0 (supported until 31 Mar 2029).

The newest actively supported branch is Ruby 4.0 (latest release 4.0.6). Review ruby-lang.org before upgrading.

Frequently asked questions

Is Ruby 3.1 still safe to use?

No. Ruby 3.1 stopped receiving security fixes on 26 Mar 2025. Since then, 1 Ruby vulnerabilities have been published and fixed in supported branches — Ruby 3.1 received none of those fixes.

Can I still download Ruby 3.1?

Yes — the final release (3.1.7) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.

What should I upgrade Ruby 3.1 to?

Upgrade to Ruby 4.0, the newest actively supported branch (supported until 31 Mar 2029).

All Ruby versions