Spring End-of-Life Resource Hub
End of life doesn’t have to mean end of support. Find strategies, resources, and solutions for keeping your Spring applications stable, secure, and compliant.

Spring Migration Calculator
Estimate the time, risk, and effort required to migrate from Spring Boot 3.5 to Spring Boot 4 before end-of-life.
This Spring Boot 3 → 4 Migration Calculator helps you estimate the real-world effort required based on application size, dependencies, team capacity, and mandatory platform upgrades, so you can plan ahead before Spring Boot 3.5 reaches end of life.
For what the estimator is, how to use it, and why it matters as Spring Boot end-of-life approaches, click here to learn more
Featured Articles
Browse expert insights, industry news, analyses, and how-tos on navigating Spring and Java end-of-life transitions.
Explore CVEs in Spring
Monitor and learn more about known vulnerabilities in legacy Spring and other popular Java libraries.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Data REST
Information Exposure
>=3.5.0 <=3.5.12, >= 3.6.0 < 3.6.7, >= 3.7.0, < 3.7.3
Mar 24, 2026
Low
Spring
Spring Cloud Contract
Information Exposure
>=3.1.0 <3.1.10, >=4.0.0 <4.0.5, =4.1.0
Mar 24, 2026
Medium
Spring
Spring Cloud Config
Path Traversal
<3.1.13, >=4.1.0 <4.1.9, >=4.2.0 < 4.2.6, >=4.3.0 <4.3.2, >5.0.0 <5.0.2
Mar 24, 2026
Critical
Spring
Spring Security
Incorrectly Configured Access Control
>=4.0.2 <6.5.9, >=7.0.0 <7.0.4
Mar 20, 2026
High
Spring
Spring Boot
Authorization Bypass
>=3.4.0 <=3.4.14, >=3.5.0 <=3.5.11, >=4.0.0 <=4.0.3
Mar 20, 2026
Low
Spring
Spring Framework
Content Spoofing
>=4.3.0 <=4.3.30, >=5.3.0 <=5.3.46, >=6.1.0 <=6.1.25, >=6.2.0 <=6.2.16, >=7.0.0 <=7.0.5
Mar 20, 2026
Medium
Spring
Spring Framework
Path Traversal
>=4.2.0 <=6.2.16, >=7.0.0 <=7.0.5
Mar 20, 2026
High
Spring
Spring Data Geode
Path Traversal
>= 2.0.0 <= 2.7.18, >= 1.7.0 <= 2.2.13
Feb 20, 2026
Medium
Spring
Spring Data Geode
Creation of Temporary File in Directory with Insecure Permissions
>= 2.0.0 < 2.7.18, >= 1.7.0 <= 2.2.13
Feb 19, 2026
Medium
Spring
Apache Kafka
Inconsistent Interpretation of HTTP Requests
>=2.3.0 <=3.5.2 >=3.6.0 <=3.6.2 =3.7.0
Dec 16, 2025
Featured Whitepaper
Deep-dive reports and technical briefings on migration, risk, and long-term Spring strategy.
Java in 2025:
Navigating Migration, Security, and Long-Term Risk
The question for CIOs, CISOs, and engineering leaders is no longer whether to continue relying on Java. It is how to migrate safely between LTS versions, reduce exposure in legacy environments, and implement governance frameworks that withstand regulatory scrutiny.This white paper provides detailed analysis of migration realities, real-world breach lessons, supply-chain risk, and the economic, regulatory, and vendor dynamics shaping enterprise decisions in 2025.

CVEs Explained
Go under the hood of major Spring CVEs as our team dissects the exploit, explains the patch, and shows you how to defend your stack.
CVE-2025-48976
Denial of Service
High
Project Affected:
Apache Commons Fileupload in Struts
Versions:
>=1.0 <1.6.0
>=2.0.0-M1 <2.0.0-M
CVE-2025-46701
Path Traversal
High
Project Affected:
Apache Tomcat in Apache Tomcat
Versions:
>=9.0.0.M1 <9.0.105
>=10.1.0-M1 <10.1.41
>=11.0.0-M1 <11.0.7
CVE-2025-31651
Command Injection
Critical
Project Affected:
Apache Tomcat in Apache Tomcat
Versions:
>=9.0.76 <9.0.104
>=10.1.10 <10.1.40
>=11.0.0-M2 <11.0.6
CVE-2025-48734
Remote Code Execution
High
Project Affected:
Apache Commons Beanutils in Struts
Versions:
>=1.0 <1.11
>=2.0.0-M1 <2.0.0-M2
Get Started
.png)
.png)
.png)


%20(1).webp)

.png)
.png)
.png)
.png)




.png)
.png)
.png)
.png)
![CVE-2024-38828: DoS via Spring MVC Controller Method with byte[] Parameter](https://cdn.prod.website-files.com/62876589ec366575fa309b1e/673e0f6a7971ec7d5afa92c9_CVE-2024-38828.png)
.png)



.png)
.png)

.png)
.png)
.png)
