Ruby 2.3 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
Ruby 2.3 reached end of life on 31 Mar 2019. It no longer receives security fixes.
Support timeline
Official dates from the Ruby release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 24 Dec 2015 | — |
| End of life | 31 Mar 2019 | 7.4 years ago |
| Latest release | 2.3.8 · 17 Oct 2018 | final |
The cost of staying: CVEs since end of life
29 Ruby vulnerabilities have been published since 31 Mar 2019. All were fixed in supported branches — 2.3 received none of them. Source: NVD.
Ruby CVEs published since 2.3's EOL, by year
4 of the 29 are rated critical · data refreshed 2026-08-09
Published 26 Nov 2019 · rated critical — fixed in supported branches only, never in 2.3. Details
Published 6 Feb 2022 · rated critical — fixed in supported branches only, never in 2.3. Details
Published 9 May 2022 · rated critical — fixed in supported branches only, never in 2.3. Details
Where to go from 2.3
Recommended target: Ruby 4.0 (supported until 31 Mar 2029).
The newest actively supported branch is Ruby 4.0 (latest release 4.0.6). Review ruby-lang.org before upgrading.
Frequently asked questions
Is Ruby 2.3 still safe to use?
No. Ruby 2.3 stopped receiving security fixes on 31 Mar 2019. Since then, 29 Ruby vulnerabilities have been published and fixed in supported branches — Ruby 2.3 received none of those fixes.
Can I still download Ruby 2.3?
Yes — the final release (2.3.8) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Ruby 2.3 to?
Upgrade to Ruby 4.0, the newest actively supported branch (supported until 31 Mar 2029).