Lodash End of Life - Dates and Lifecycle
Lodash is a JavaScript utility library providing modular, high-performance functions for common programming tasks like array manipulation, object iteration, and deep cloning.
Last updated 24 July 2026
10
Versions tracked
9
At EOL
1
Supported
All versions
| Version | Released | Security Support | Latest |
|---|---|---|---|
|
4.18.1
|
01 Apr 2026 | — | — |
|
4.18.0
|
31 Mar 2026 |
01 Apr 2026
Ended 3 months, 3 weeks ago
|
— |
|
4.17.23
|
21 Jan 2026 |
31 Mar 2026
Ended 3 months, 3 weeks ago
|
— |
|
4.17.21
|
20 Feb 2021 |
21 Jan 2026
Ended 6 months ago
|
— |
|
4.17.20
|
13 Aug 2020 |
20 Feb 2021
Ended 5 years, 5 months ago
|
— |
|
4.17.17
|
08 Jul 2020 |
08 Jul 2020
Ended 6 years ago
|
— |
|
4.17.19
|
08 Jul 2020 |
13 Aug 2020
Ended 5 years, 11 months ago
|
— |
|
4.17.18
|
08 Jul 2020 |
08 Jul 2020
Ended 6 years ago
|
— |
About Lodash
Lodash is a JavaScript utility library providing well-tested, high-performance functions for arrays, objects, strings, and other common programming tasks. First released in 2012 as a fork of Underscore.js, it became the single most depended-on package in the npm ecosystem, with hundreds of thousands of projects relying on it directly and many more through nested dependencies.
Lodash Lifecycle Explained
Lodash's official policy is simple: only the latest patch of any release line is supported. Once a new version ships, the previous one is immediately considered end of life, it may still receive a fix for a critical vulnerability, but the maintainers make no guarantee of that. There's no scheduled retirement date the way an operating system or language runtime has, supersession itself is what ends a version's support.
What makes Lodash's history unusual is a long gap in that supersession process. Version 4.17.21, released in February 2021, patched a command-injection vulnerability in _.template and a regular-expression denial-of-service issue. It then remained the latest release for almost five years, with no further patches shipping at all. That silence fueled a real "is Lodash dead" narrative across the JavaScript community and helped drive interest in newer alternatives, even as Lodash itself continued to be downloaded by the millions.
That changed in 2025, when the OpenJS Foundation announced Sovereign Tech Agency funding for Lodash and a new governance structure, moving the project toward what it called a "Feature-Complete maturity stage" with a dedicated Technical Steering Committee. The first release after the long gap was 4.17.23 in January 2026, which patched a prototype pollution flaw in _.unset and _.omit that in fact dated all the way back to version 4.0.0, disclosed as CVE-2025-13465. Further releases, 4.18.0 and 4.18.1, followed within a few months. A long-promised Lodash 5 has still never materialized, despite years of community speculation about it.
Frequently Asked Questions
Is Lodash still needed in 2026?
For projects already using it, yes, it remains a stable, widely trusted utility library, and its renewed governance and funding suggest it isn't going away. For new projects, native JavaScript has absorbed many of the features Lodash was originally needed for, and lighter alternatives exist, so the calculus is more genuinely open than it was a decade ago.
Is Lodash outdated?
It was showing real signs of that during its roughly five-year gap without a release, which is exactly what fueled the "Lodash is dead" conversation. Since the 2025 revival brought new funding, governance, and active patching, that characterization is now out of date itself.
What is the latest version of Lodash?
Lodash 4.18.1, released in April 2026, is the current version. It followed a rapid run of releases (4.17.23, 4.18.0) after the project's multi-year quiet period ended.
Is Lodash 4.17.21 vulnerable?
Yes. Although it was the trusted, stable version of record for years, Lodash's new maintainers later disclosed a prototype pollution vulnerability (CVE-2025-13465) affecting versions from 4.0.0 through 4.17.21. The fix is in 4.17.23 and later.
Which version fixed Lodash's prototype pollution vulnerabilities?
The prototype pollution issue in _.unset and _.omit, tracked as CVE-2025-13465, is fixed starting in version 4.17.23. Everything from 4.0.0 through 4.17.21, including the long-standing 4.17.21 release itself, is affected.