Ruby on Rails 5.2 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
Ruby on Rails 5.2 reached end of life on 1 Jun 2022. It no longer receives security fixes.
Support timeline
Official dates from the Ruby on Rails release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 9 Apr 2018 | — |
| End of life | 1 Jun 2022 | 4.2 years ago |
| Active support ended | 15 Dec 2021 | security fixes only after this |
| Latest release | 5.2.8.1 · 12 Jul 2022 | final |
The cost of staying: CVEs since end of life
18 Ruby on Rails vulnerabilities have been published since 1 Jun 2022. All were fixed in supported branches — 5.2 received none of them. Source: NVD.
Ruby on Rails CVEs published since 5.2's EOL, by year
2 of the 18 are rated critical · data refreshed 2026-08-09
Published 24 Mar 2026 · rated critical — fixed in supported branches only, never in 5.2. Details
Published 24 Mar 2026 · rated critical — fixed in supported branches only, never in 5.2. Details
Published 9 Feb 2023 · rated high — fixed in supported branches only, never in 5.2. Details
Where to go from 5.2
Recommended target: Ruby on Rails 8.1 (supported until 10 Oct 2027).
The newest actively supported branch is Ruby on Rails 8.1 (latest release 8.1.3.1).
Frequently asked questions
Is Ruby on Rails 5.2 still safe to use?
No. Ruby on Rails 5.2 stopped receiving security fixes on 1 Jun 2022. Since then, 18 Ruby on Rails vulnerabilities have been published and fixed in supported branches — Ruby on Rails 5.2 received none of those fixes.
Can I still download Ruby on Rails 5.2?
Yes — the final release (5.2.8.1) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Ruby on Rails 5.2 to?
Upgrade to Ruby on Rails 8.1, the newest actively supported branch (supported until 10 Oct 2027).