Visit NES for Spring Home Page

Spring Framework 6.2.x Release Notes

2 versions

Comprehensive release notes and changelog for Spring Framework 6.2.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 25, 2026
Latest: 6.2.21
60 Patched Vulnerabilities
VEX Statements

August 2026

Full Version:
6.2.19-spring-framework-6.2.21

Security Fixes

  • Control characters in form field names or filenames can no longer split an HTTP response through ContentDisposition when the connector does not reject them (low severity, CVE-2026-59314).
  • Malformed WebSocket handshake headers no longer cause HandshakeWebSocketService to include all request headers, including sensitive values, in an exception reason (low severity, CVE-2026-47893).
  • Line separators in Server-Sent Event field values can no longer inject additional fields through SseServerResponse and corrupt the event stream (low severity, CVE-2026-59313).
  • Bare carriage returns in view fragments rendered by ViewResolutionResultHandler and ResponseBodyEmitterReturnValueHandler can no longer terminate an SSE field and corrupt the event stream (low severity, CVE-2026-47890).
  • A self-populating List can no longer bypass the auto-grow collection limit configured on AbstractNestablePropertyAccessor during attacker-controlled property-path traversal (medium severity, CVE-2026-59282).
  • Unescaped rejected values and messages are no longer exposed to views by the EscapedErrors no-argument field error accessors (medium severity, CVE-2026-59281).
  • Asynchronous XML parsing in Jaxb2XmlDecoder no longer retains aggregated events beyond the configured maxInMemorySize limit (medium severity, CVE-2026-47891).
  • Configured SameSite cookie attributes are no longer omitted from Jetty Core responses written by JettyCoreServerHttpResponse (medium severity, CVE-2026-47889).
  • Malformed SETUP metadata no longer leaves a retained ConnectionSetupPayload buffer unreleased in MessagingRSocket (medium severity, CVE-2026-47888).
  • Attacker-controlled exponents can no longer drive OperatorPower to create unbounded BigDecimal or BigInteger results and exhaust CPU or heap (medium severity, CVE-2026-47886).
    • A BigDecimal or BigInteger power operation in a SpEL expression whose estimated result exceeds 1,000,000 bits — roughly a 300,000-digit decimal number — now throws a SpelEvaluationException instead of computing the result. Applications that legitimately perform large power arithmetic can raise or remove this limit by setting the spring.expression.maxBigPowerBits JVM system property (or the equivalent Spring property), or by passing a custom maximumBigPowerBits value to the SpelParserConfiguration constructor — use Integer.MAX_VALUE for no limit.
  • A configured maxPartSize is now enforced by PartEventHttpMessageReader even when maxInMemorySize is unlimited (medium severity, CVE-2026-47885).
  • A CORS preflight request can no longer invoke a route handler matched against the would-be actual request in RouterFunctionWebHandler when using toHttpHandler without DispatcherHandler (medium severity, CVE-2026-47892).
  • Globally enabled SpEL compilation no longer bypasses the restrictions SimpleEvaluationContext enforces during interpreted evaluation (medium severity, CVE-2026-59283).
    • SpEL expression compilation is now disabled by default for SimpleEvaluationContext. Applications that relied on spring.expression.compiler.mode or SpelParserConfiguration to compile expressions evaluated in a SimpleEvaluationContext will now fall back to interpreted evaluation, and can opt back in with the new SimpleEvaluationContext.Builder.withCompilationSupported() method. An already-compiled expression is ignored — not cleared — when evaluated through a context that does not support compilation.
    • EvaluationContext also gains a new isCompilationSupported() default method, which an implementation may override to declare that expressions evaluated within it may not be compiled. Existing EvaluationContext implementations are unaffected and continue to support compilation.
  • Template names containing backslashes can no longer escape the configured template directory through SpringTemplateLoader.findTemplateSource() (medium severity, CVE-2026-59280).
  • A request-derived view name that still begins with redirect: or forward: once the configured prefix and suffix are applied is now rejected with a 400 Bad Request by UrlFilenameViewController instead of triggering navigation (medium severity, CVE-2026-47887).
  • A request path beginning with two slashes no longer produces a protocol-relative redirect to an attacker-controlled host in UrlHandlerFilter (medium severity, CVE-2026-47883).
  • An untrusted view URL can no longer select an arbitrary stylesheet resource location through XsltView.getStylesheetSource() (critical severity, CVE-2026-47884).

July 2026

6.2.20

Released Jul 9, 2026
Full Version:
6.2.19-spring-framework-6.2.20

Notes

  • This release originates from the open‑source Spring Framework repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Framework 6.2.19.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.