Visit NES for Spring Home Page

Spring GraphQL 1.4.x Release Notes

2 versions

Comprehensive release notes and changelog for Spring GraphQL 1.4.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 28, 2026
Latest: 1.4.8
7 Patched Vulnerabilities
VEX Statements

August 2026

Full Version:
1.4.6-spring-graphql-1.4.8

Security Fixes

  • Cancelling a WebSocket session no longer leaves a duplicate keepalive interval active in WebSocketGraphQlTransport, so repeated reconnects can no longer exhaust application memory (medium severity, CVE-2026-59287).
  • Client-supplied Connection pagination counts no longer reach repositories unbounded, because ScrollableEntityFetcher now clamps a requested count down to a configurable maximum of 100 elements (high severity, CVE-2026-59289).
  • GraphiQL no longer loads remote assets without Subresource Integrity (high severity, CVE-2026-59286), and endpoint query parameters can no longer resolve to an external origin (high severity, CVE-2026-59288).

Dependency Upgrades

  • Spring Data BOM (NES) 2025.0.13-spring-data-bom-2025.0.15
  • Spring Framework (NES) 6.2.19-spring-framework-6.2.21
  • Spring Security (NES) 6.5.11-spring-security-6.5.13

July 2026

1.4.7

Released Jul 9, 2026
Full Version:
1.4.6-spring-graphql-1.4.7

Notes

  • This release originates from the open‑source Spring GraphQL repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring GraphQL 1.4.6.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.