Spring End-of-Life Resource Hub

End of life doesn’t have to mean end of support. Find strategies, resources, and solutions for keeping your Spring applications stable, secure, and compliant.

Spring EOL Resource Hub
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

EOL Calendar

Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Spring Framework Logo
Spring
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
Spring Boot 3.5.6 (Sep 18, 2025)
Spring Boot 3.4.10 (Sep 18, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
Apache Tomcat logo
Apache Tomcat
Tomcat 8.5.101 (NES) (Jul 10, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Tomcat 8.5.102 (NES) (Jul 23, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Tomcat 11.0.11 (Sep 05, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Struts logo
Apache Struts
Struts 7.0.3 (GA) (Mar 03, 2025)
Struts 6.7.4 (GA) (Mar 05, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
Solr logo
Apache Solr
Solr 8.11.5 (NES) (Mar 25, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Solr 9.9.0 (Jul 24, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Apache Tapestry logo
Apache Tapestry
Tapestry 5.9.0 (Feb 11, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Tapestry 4.1.x (NES) (Apr 04, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Apache Camel logo
Apache Camel
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.10.4 (LTS) (Apr 30, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.8.7 (LTS) (May 09, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.12.0 (May 29, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.10.5 (LTS) (Jun 03, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.8.8 (LTS) (Jun 26, 2025)
Camel 4.10.6 (LTS) (Jun 27, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.13.0 (Jul 08, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.14.0 (LTS) (Aug 19, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Camel 4.8.9 (LTS) (Sep 17, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Apache Spark logo
Apache Spark
Spark 2.4.x (NES) (Apr 02, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Spark 4.0.0 (May 23, 2025)
Spark 3.5.6 (May 29, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Spark 4.0.1 (Sep 06, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Apache Cocoon logo
Apache Cocoon
EOL
Enters LTS
New OSS Version release
New NES Version Release
Coccon 2.3.x (NES) (Apr 08, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release
Hibernate logo
Hibernate
EOL
Enters LTS
New OSS Version release
New NES Version Release
EOL
Enters LTS
New OSS Version release
New NES Version Release
Hibernate 5.6 (Sep 25, 2025)
EOL
Enters LTS
New OSS Version release
New NES Version Release

Explore CVEs on EOL Java Versions

View All
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Framework
Privilege Abuse
>=5.3.0 <=5.3.44, >=6.0.0 <=6.0.29, >=6.1.0 <6.1.23, >=6.2.0 <6.2.11
Sep 22, 2025
High
Angular
@angular/platform-server, @angular/ssr, @nguniversal/common
Information Exposure
@angular/platform-server, =16.0.0-next.0 <18.2.14, >=19.0.0-next.0 <19.2.15, >=20.0.0-next.0 <20.3.0, >=21.0.0-next.0 <21.0.0-next.3, @angular/ssr, =17.0.0-next.0 <18.2.21, >=19.0.0-next.0 <19.2.16, >=20.0.0-next.0 <20.3.0, >=21.0.0-next.0 <21.0.0-next.3, @nguniversal/common, =16.0.0-next.0
Sep 11, 2025
Critical
Spring
Spring Cloud Gateway
Incorrectly Configured Access Control
>=3.1.0 <=3.1.9, >=4.0.0 <=4.0.9, >=4.1.0 <=4.1.9, >=4.2.0 <4.2.5, >=4.3.0 <4.3.1
Sep 10, 2025
Medium
Drupal 7
Access Code Drupal module
Broken Access
<=7.1.1
Aug 26, 2025
Medium
AngularJS
AngularJS
Regular Expression Denial of Service
>=0.0.0
Aug 19, 2025
Medium
Spring
Spring Framework
Path Traversal
>=4.3.0 <=4.3.30, >=5.3.0 <=5.3.43, >=6.0.0 <=6.0.29, >=6.1.0 <=6.1.21, >=6.2.0 <=6.2.9
Aug 18, 2025
Low
Struts
Apache Struts
Log Injection
>=1.2.9 <=1.3.10
Aug 4, 2025
High
Struts
Apache Commons Beanutils
Remote Code Execution
>=1.0 <1.11, >=2.0.0-M1 <2.0.0-M2
Aug 4, 2025
High
Struts
Apache Commons Fileupload
Denial of Service
>=1.0 <1.6.0, >=2.0.0-M1 <2.0.0-M
Aug 4, 2025
High
Apache Tomcat
Apache Tomcat
Path Traversal
>=9.0.0.M1 <9.0.105, >=10.1.0-M1 <10.1.41, >=11.0.0-M1 <11.0.7
Aug 4, 2025
Critical
Apache Tomcat
Apache Tomcat
Command Injection
>=9.0.76 <9.0.104, >=10.1.10 <10.1.40, >=11.0.0-M2 <11.0.6
Aug 4, 2025
Critical
Apache Tomcat
Apache Tomcat
Remote Code Execution
>=9.0.0.M1 <9.0.99, >=10.1.0-M1 <10.1.35, >=11.0.0-M1 <11.0.3
Jul 30, 2025
Medium
Apache Tomcat
Apache Tomcat
Denial of Service
>=9.0.0.M1 <9.0.107, >=10.1.0-M1 <10.1.43, >=11.0.0-M1 <11.0.9
Jul 30, 2025
Medium
Apache Tomcat
Apache Tomcat
Denial of Service
>=9.0.0.M1 <9.0.107, >=10.1.0-M1 <10.1.43, >=11.0.0-M1 <11.0.9
Jul 30, 2025
Medium
Apache Tomcat
Apache Tomcat
Denial of Service
>=9.0.0.M1 <9.0.107
Jul 30, 2025

Featured Whitepaper

View All

Maximize the Value of Legacy Software Without Adding to Your Tech Debt

Financial institutions face a unique challenge: maintaining secure, compliant, and innovative operations in a rapidly evolving digital landscape. As open-source software (OSS) becomes central to driving innovation, the end-of-life (EOL) of OSS presents new risks. Through real-world examples, we demonstrate how financial institutions can effectively manage OSS to safeguard operations, maintain compliance, and protect their reputations.
Maximize the Value of Legacy Software Without Adding 
to Your Tech Debt
Shorts
View All