Spring End-of-Life Resource Hub
End of life doesn’t have to mean end of support. Find strategies, resources, and solutions for keeping your Spring applications stable, secure, and compliant.

Spring Migration Calculator
Estimate the time, risk, and effort required to migrate from Spring Boot 3.5 to Spring Boot 4 before end-of-life.
This Spring Boot 3 → 4 Migration Calculator helps you estimate the real-world effort required based on application size, dependencies, team capacity, and mandatory platform upgrades, so you can plan ahead before Spring Boot 3.5 reaches end of life.
For what the estimator is, how to use it, and why it matters as Spring Boot end-of-life approaches, click here to learn more
Featured Articles
Browse expert insights, industry news, analyses, and how-tos on navigating Spring and Java end-of-life transitions.
Explore CVEs in Spring
Monitor and learn more about known vulnerabilities in legacy Spring and other popular Java libraries.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Cloud Config
Information Exposure
>=1.3.0 <=3.1.13, >=4.1.0 <=4.1.9, >=4.2.0 <=4.2.6, >=4.3.0 <=4.3.2, >=5.0.0 <=5.0.2
May 7, 2026
High
Spring
Spring Cloud Config
Path Traversal
>=1.0.0 <=3.1.13, >=4.1.0 <=4.1.9, >=4.2.0 <=4.2.6, >=4.3.0 <=4.3.2, >=5.0.0 <=5.0.2
May 7, 2026
High
Spring
Spring Cloud Config
Information Exposure
>=3.1.0 <=3.1.13, >=4.1.0 <=4.1.9, >=4.2.0 <=4.2.6, >=4.3.0 <=4.3.2, >=5.0.0 <=5.0.2
May 7, 2026
Critical
Spring
Spring Cloud Config
Path Traversal
>=1.0.0 <=3.1.13, >=4.1.0 <=4.1.9, >=4.2.0 <=4.2.6, >=4.3.0 <=4.3.2, >=5.0.0 <=5.0.2
May 7, 2026
Medium
Spring
Spring Boot
Denial of Service
>=2.5.0 <=2.7.17, >=3.0.0 <=3.0.12, >=3.1.0 <=3.1.5
May 1, 2026
Medium
Spring
Spring AMQP
Remote Code Execution
>=1.0.0 <=2.4.16, >=3.0.0 <=3.0.9
May 1, 2026
Medium
Spring
Spring Boot
Path Traversal
>=1.0.2 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 27, 2026
Medium
Spring
Spring Boot
Information Exposure
>=1.0.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 27, 2026
High
Spring
Spring Boot
Incorrectly Configured Access Control
>=2.7.0 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 27, 2026
High
Spring
Spring Boot
Information Exposure
>=1.3.0 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 27, 2026
Medium
Spring
Spring Boot
Incorrectly Configured Access Control
>=1.3.0 <=2.7.32, >=3.0.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
Critical
Spring
Spring Security
Authorization Bypass
1.3.x; 1.4.x; 1.5.x; 7.0.x
Apr 23, 2026
Medium
Spring
Spring Security
Weak Authentication
6.2.x; 6.3.x; 6.4.x; 6.5.x; 7.0.x
Apr 23, 2026
Low
Spring
Spring Security
Authorization Bypass
4.2.x; 5.5.x; 5.7.x; 5.8.x; 6.2.x; 6.3.x; 6.4.x; 6.5.x; 7.0.x
Apr 23, 2026
Featured Whitepaper
Deep-dive reports and technical briefings on migration, risk, and long-term Spring strategy.
Java in 2025:
Navigating Migration, Security, and Long-Term Risk
The question for CIOs, CISOs, and engineering leaders is no longer whether to continue relying on Java. It is how to migrate safely between LTS versions, reduce exposure in legacy environments, and implement governance frameworks that withstand regulatory scrutiny.This white paper provides detailed analysis of migration realities, real-world breach lessons, supply-chain risk, and the economic, regulatory, and vendor dynamics shaping enterprise decisions in 2025.

CVEs Explained
Go under the hood of major Spring CVEs as our team dissects the exploit, explains the patch, and shows you how to defend your stack.
CVE-2025-48976
Denial of Service
High
Project Affected:
Apache Commons Fileupload in Struts
Versions:
>=1.0 <1.6.0
>=2.0.0-M1 <2.0.0-M
CVE-2025-46701
Path Traversal
High
Project Affected:
Apache Tomcat in Apache Tomcat
Versions:
>=9.0.0.M1 <9.0.105
>=10.1.0-M1 <10.1.41
>=11.0.0-M1 <11.0.7
CVE-2025-31651
Command Injection
Critical
Project Affected:
Apache Tomcat in Apache Tomcat
Versions:
>=9.0.76 <9.0.104
>=10.1.10 <10.1.40
>=11.0.0-M2 <11.0.6
CVE-2025-48734
Remote Code Execution
High
Project Affected:
Apache Commons Beanutils in Struts
Versions:
>=1.0 <1.11
>=2.0.0-M1 <2.0.0-M2
Get Started
.png)
.png)
.png)








.png)


%20(1).webp)

.png)
.png)
.png)
.png)




.png)
.png)
.png)
.png)
![CVE-2024-38828: DoS via Spring MVC Controller Method with byte[] Parameter](https://cdn.prod.website-files.com/62876589ec366575fa309b1e/673e0f6a7971ec7d5afa92c9_CVE-2024-38828.png)
.png)



.png)
.png)

.png)
.png)
.png)
