Visit NES for Spring Home Page
Spring GraphQL 1.4.x Release Notes
2 versions
Comprehensive release notes and changelog for Spring GraphQL 1.4.x, including security patches, bug fixes, and feature updates across all supported versions.
August 2026
1.4.8
Released Aug 28, 2026 Full Version:
1.4.6-spring-graphql-1.4.8
Security Fixes
- Cancelling a WebSocket session no longer leaves a duplicate keepalive interval active in
WebSocketGraphQlTransport, so repeated reconnects can no longer exhaust application memory (medium severity, CVE-2026-59287). - Client-supplied Connection pagination counts no longer reach repositories unbounded, because
ScrollableEntityFetchernow clamps a requested count down to a configurable maximum of 100 elements (high severity, CVE-2026-59289). GraphiQLno longer loads remote assets without Subresource Integrity (high severity, CVE-2026-59286), and endpoint query parameters can no longer resolve to an external origin (high severity, CVE-2026-59288).
Dependency Upgrades
- Spring Data BOM (NES)
2025.0.13-spring-data-bom-2025.0.15 - Spring Framework (NES)
6.2.19-spring-framework-6.2.21 - Spring Security (NES)
6.5.11-spring-security-6.5.13
July 2026
1.4.7
Released Jul 9, 2026 Full Version:
1.4.6-spring-graphql-1.4.7
Notes
- This release originates from the open‑source Spring GraphQL repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring GraphQL
1.4.6.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh