Visit NES for Spring Home Page

Spring Security 6.5.x Release Notes

2 versions

Comprehensive release notes and changelog for Spring Security 6.5.x, including security patches, bug fixes, and feature updates across all supported versions.

Aug 28, 2026
Latest: 6.5.13
22 Patched Vulnerabilities
VEX Statements

August 2026

Full Version:
6.5.11-spring-security-6.5.13

Security Fixes

  • A UserVerificationRequirement restored from a serialized session is again recognized as requiring user verification, so WebAuthn authentication is no longer silently weakened (high severity, CVE-2026-47841).
  • An embedded LDAP server started by UnboundIdContainer no longer listens on every network interface with a well-known administrative credential, binding to loopback unless another address is configured (critical severity, CVE-2026-59270).
  • Flooding the jti cache can no longer evict a captured DPoP proof's identifier and let that proof be replayed, because DPoPProofJwtDecoderFactory now delegates replay detection to a dedicated DPoPProofReplayValidator instead of a fixed-size cache (high severity, CVE-2026-41707).
  • Secret-bearing values are no longer compared with timing-variable equality checks in DigestAuthenticationFilter and KeyBasedPersistenceTokenService, which now use a constant-time comparison (medium severity, CVE-2026-59276).
  • AesBytesEncryptor and the Encryptors factory methods are now deprecated but still encrypt CBC with an all-zero initialization vector, so identical plaintexts still produce identical ciphertext for a given password and salt; remediation is a migration to the new AesCbcBytesEncryptor or AesGcmBytesEncryptor, which requires re-encrypting existing data (medium severity, CVE-2026-47842).
    • See the guide for more information on migrating to the replacement encryptors.

Dependency Upgrades

  • Spring Framework (NES) 6.2.19-spring-framework-6.2.21

July 2026

6.5.12

Released Jul 9, 2026
Full Version:
6.5.11-spring-security-6.5.12

Notes

  • This release originates from the open‑source Spring Security repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Security 6.5.11.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.