Visit NES for Spring Home Page

Spring Security 6.3.x Release Notes

5 versions

Comprehensive release notes and changelog for Spring Security 6.3.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 28, 2026
Latest: 6.3.15
110 Patched Vulnerabilities
VEX Statements

August 2026

Full Version:
6.3.10-spring-security-6.3.15

Security Fixes

  • An embedded LDAP server started by UnboundIdContainer no longer listens on every network interface with a well-known administrative credential, binding to loopback unless another address is configured (critical severity, CVE-2026-59270).
  • Secret-bearing values are no longer compared with timing-variable equality checks in DigestAuthenticationFilter and KeyBasedPersistenceTokenService, which now use a constant-time comparison (medium severity, CVE-2026-59276).
  • AesBytesEncryptor and the Encryptors factory methods are now deprecated but still encrypt CBC with an all-zero initialization vector, so identical plaintexts still produce identical ciphertext for a given password and salt; remediation is a migration to the new AesCbcBytesEncryptor or AesGcmBytesEncryptor, which requires re-encrypting existing data (medium severity, CVE-2026-47842).
    • See the guide for more information on migrating to the replacement encryptors.

Dependency Upgrades

  • Spring Data BOM (NES) 2024.0.13-spring-data-bom-2024.0.18
  • Spring Framework (NES) 6.1.21-spring-framework-6.1.30
  • Spring LDAP (NES) 3.2.16-spring-ldap-3.2.23

June 2026

Full Version:
6.3.10-spring-security-6.3.14

Security Fixes

  • Capped the inflated size of compressed SAML 2.0 REDIRECT-binding payloads in Saml2Utils, preventing an unauthenticated attacker from exhausting server memory (CVE-2026-40988).
  • Hardened the SAML 2.0 filters to route generated HTML forms through FormPostRedirectStrategy, preventing arbitrary code execution via attacker-influenced RelyingPartyRegistration values (CVE-2026-41003).
  • Reworked SAML login and logout validation so signature validation gates decryption, closing a decryption-oracle weakness in the OpenSAML authentication and logout providers (CVE-2026-41694).
  • Fixed an open-redirect vulnerability in CookieRequestCache and CookieServerRequestCache, which stored and used an unvalidated absolute redirect URL; saved requests now favor relative URIs (CVE-2026-41706).
  • Tightened Subject DN parsing in the deprecated SubjectDnX509PrincipalExtractor, preventing a crafted X.509 client certificate from authenticating as another user (CVE-2026-47838).

Dependency Upgrades

  • Spring Data BOM (NES) 2024.0.13-spring-data-bom-2024.0.17
  • Spring Framework (NES) 6.1.21-spring-framework-6.1.28

April 2026

Full Version:
6.3.10-spring-security-6.3.13

Security Fixes

  • Patched the authorization bypass in DaoAuthenticationProvider where timing attack protections could be circumvented for disabled, expired, or locked accounts when applications rely on UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked (CVE-2026-22746).
  • Patched the weak authentication issue in NimbusJwtDecoder and NimbusReactiveJwtDecoder where JWT token validation is not enforced unless an OAuth2TokenValidator<Jwt> is explicitly configured via setJwtValidator() (CVE-2026-22748).

Dependency Upgrades

  • Spring Data BOM (NES) 2024.0.13-spring-data-bom-2024.0.16
  • Spring Framework (NES) 6.1.21-spring-framework-6.1.27
  • Spring LDAP (NES) 3.2.16-spring-ldap-3.2.20

March 2026

6.3.12

Released Mar 23, 2026
Full Version:
6.3.10-spring-security-6.3.12

Security Fixes

  • Patched the critical Spring Security vulnerability in OnCommittedResponseWrapper where security headers are silently dropped when Content-Length is set via setHeader, setIntHeader, or addIntHeader (CVE-2026-22732).

Dependency Upgrades

  • Spring Framework (NES) 6.1.21-spring-framework-6.1.26

December 2025

6.3.11

Released Dec 10, 2025
Full Version:
6.3.10-spring-security-6.3.11

Notes

  • This release originates from the open‑source Spring Security repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Security 6.3.10.

Dependency Upgrades

  • Spring Data BOM (NES) 2024.0.13-spring-data-bom-2024.0.14
  • Spring Framework (NES) 6.1.21-spring-framework-6.1.25Full Version: 6.3.10-spring-security-6.3.11

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.