OSSEVA FOR ELASTICSEARCH

Elasticsearch support for 7.x, patched after end of support.

OSSeva provides Elasticsearch support for self-managed 7.10.2, 7.17 and 8.x, including patched builds for 7.10.2 and 7.17 after Elastic stops fixing them, and for 8.19 once Elastic ends 8.x maintenance on 15 January 2027. When your indices and clients are ready, we plan the route to 9.x or OpenSearch.

Last reviewed

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

7.10.2 is the last Apache-2.0 Elasticsearch

From 7.11 Elastic moved Elasticsearch to SSPL and the Elastic License, and 7.x never received the AGPL option added in 8.16. Teams that cannot accept the later licences, and products that embed Elasticsearch, have stayed on 7.10.2 ever since, and nobody upstream patches it.

8.x needs a reindex, not just an upgrade

Elasticsearch 8.x cannot read indices created in 6.x or earlier, removes mapping types, and enables security by default. Old indices have to be reindexed and clients updated, which is why so many clusters are still on 7.17.

Advisories keep landing with no 7.x fix

Elasticsearch 7.17 reached end of life on 15 January 2026, and 7.17.29 was its last release. CVE-2025-37731 (PKI realm user impersonation) and CVE-2025-68384 (node crash by a low-privileged user) affect every 7.x release and were fixed only in 8.19 and 9.x.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
7.10.2(Last Apache-2.0 release)ExtendedClean
7.17(EOL 15 Jan 2026; last release 7.17.29)ExtendedClean
8.x(Elastic maintenance to 15 Jan 2027; OSSeva backports to 8.19 after)CurrentClean
OpenSearch 2.x(Migration target)CurrentClean
Every Elasticsearch version and end-of-life date →Every OpenSearch version and end-of-life date →

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Security fixes for Elasticsearch 7.10.2 and 7.17.

  • Backported security fixes for Elasticsearch and its bundled libraries
  • Bundled JDK updates
  • Packages and container images
  • Signed artifacts and SBOMs
  • Advisory notifications
  • Migration planning
Get started →
Most popular

OSSeva Assure

Patch plus security hardening and a migration plan.

  • Everything in Patch
  • Security and network exposure review
  • Reindex and client plan for 8.x or OpenSearch
  • SOC 2 / PCI DSS evidence pack
  • 24/7 managed operations
Get started →

OSSeva Operate

Managed operations for self-managed search clusters.

  • Everything in Assure
  • 24/7 cluster health monitoring
  • 15-minute P1 incident response
  • Executed migrations to 8.x or OpenSearch
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Find indices that block an 8.x upgradebash
# Indices created before 7.0 must be reindexed before 8.x
curl -s 'localhost:9200/_all/_settings/index.version.created*?pretty' | grep -B2 '"6'

# The upgrade assistant's deprecation report
curl -s 'localhost:9200/_migration/deprecations?pretty'

Migrate from Amazon OpenSearch Service Extended Support

AWS charges Extended Support on older Elasticsearch versions in OpenSearch Service. Self-managed clusters on patched 7.x builds avoid the surcharge while the migration is planned.

↗

Pricing model

Priced per cluster. Book a discovery call for a quote.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Is Elasticsearch 7.10.2 still open source?

Its OSS distribution is Apache 2.0, and remains so; the default distribution also bundled X-Pack under the Elastic License. From 7.11, Elasticsearch moved to SSPL and the Elastic License, which is why 7.10.2 is still widely deployed and why OpenSearch was forked from it.

Why can't we upgrade Elasticsearch 7 to 8 in place?

You can, if every index was created in 7.x and your clients are compatible. Indices created in 6.x or earlier must be reindexed first, mapping types are removed, and security is on by default in 8.x.

Should we move to OpenSearch instead of Elasticsearch 8?

If licence is the reason you are on 7.10.2, OpenSearch keeps Apache 2.0. If you rely on features added in Elastic's later releases, 8.x is the path. We help you decide per cluster.

Who provides Elasticsearch support besides Elastic?

Elastic, the company behind Elasticsearch, is the commercial vendor. Cloud providers run managed search services, and Amazon OpenSearch Service charges Extended Support on older Elasticsearch versions. Third-party support companies cover the self-managed clusters you run yourself. OSSeva is a third-party provider: one contract can cover Elasticsearch and the rest of your open source stack, end-of-life 7.10.2 and 7.17 are included, and it works on your self-managed clusters.

Does OSSeva support current Elasticsearch versions or only end-of-life ones?

Both. Self-managed 8.x is covered as a current line, with OSSeva backporting fixes to 8.19 after Elastic ends 8.x maintenance on 15 January 2027, and 7.10.2 and 7.17 get patched builds after end of support. OpenSearch 2.x is a migration target: Assure plans the reindex and client changes for 8.x or OpenSearch, and Operate executes the migration.

How is OSSeva Elasticsearch support priced?

OSSeva for Elasticsearch is priced per cluster. The tier you choose (Patch, Assure or Operate) sets what is included, and Operate adds 24/7 cluster health monitoring with a 15-minute P1 incident response. Book a discovery call for a quote.

Ready to get Elasticsearch patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.