Visit NES for Spring Home Page
Spring Security 6.4.x Release Notes
2 versions
Comprehensive release notes and changelog for Spring Security 6.4.x, including security patches, bug fixes, and feature updates across all supported versions.
March 2026
6.4.15
Released Mar 23, 2026 Full Version:
6.4.13-spring-security-6.4.15
Bug Fixes
- Patched the critical Spring Security vulnerability in
OnCommittedResponseWrapperwhere security headers are silently dropped whenContent-Lengthis set viasetHeader,setIntHeader, oraddIntHeader(CVE-2026-22732).
Dependency Upgrades
- Spring Framework
6.2.17 - Spring Data BOM (NES)
2024.1.13-spring-data-bom-2024.1.14 - Spring LDAP (NES)
3.2.16-spring-ldap-3.2.18
January 2026
6.4.14
Released Jan 28, 2026 Full Version:
6.4.13-spring-security-6.4.14
Notes
- This release originates from the open‑source Spring Security repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Security
6.4.13.
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh