// OSSeva Blog
SecuritySpring Framework Vulnerabilities by Version: CVEs for 5.3.x, 6.0.x and 6.1.x
The short answer
Every Spring Framework line before 7.0 is now outside open source support. According to spring.io, open source support ended for 6.0.x on 30 June 2024, for 5.3.x on 31 August 2024, for 6.1.x on 30 June 2025 and for 6.2.x on 30 June 2026. Spring Framework 7.0 is supported until 31 July 2027. Since those dates, Spring's advisories have kept listing fixed versions for the older lines, but marked them "Enterprise Support Only", which means the fix exists and is not published to Maven Central. The tables below show, for each notable CVE, which releases are affected and where the fix is available.
How to read the tables
- Affected is the range from the spring.io advisory. "and earlier" means the advisory lists no lower bound for that line.
- Fixed is the first release with the fix. "(commercial)" means the advisory marks it Enterprise Support Only.
- Not listed means the advisory does not mention that line. It is not a statement that the line is safe.
Advisories also note that older, unsupported versions are affected. That covers 5.2.x and earlier, which this guide does not track.
2022: Spring4Shell and SpEL
| CVE | Issue | 5.3.x | 6.0.x |
|---|---|---|---|
| CVE-2022-22965 (Spring4Shell) | Remote code execution through data binding on JDK 9 and later | 5.3.0 to 5.3.17, fixed in 5.3.18 | Not listed (6.0 was not yet released) |
| CVE-2022-22950 | Denial of service through a crafted SpEL expression | 5.3.0 to 5.3.16, fixed in 5.3.17 | Not listed (6.0 was not yet released) |
CVE-2022-22965 is rated 9.8 on NVD. The published exploit needs the application to run on Tomcat as a WAR deployment, and Spring's advisory says an executable Spring Boot jar, the default, is not vulnerable to that exploit. The advisory adds that the flaw is more general and other exploit paths may exist, so the fix, not the deployment shape, is the control. 5.2.x was fixed in 5.2.20.RELEASE.
2023: request matching and more SpEL
| CVE | Issue | 5.3.x | 6.0.x |
|---|---|---|---|
| CVE-2023-20860 | Security bypass when "**" is used as a pattern with mvcRequestMatcher in Spring Security configuration | 5.3.25 and earlier, fixed in 5.3.26 | 6.0.0 to 6.0.6, fixed in 6.0.7 |
| CVE-2023-20861 | Denial of service through a crafted SpEL expression | 5.3.0 to 5.3.25, fixed in 5.3.26 | 6.0.0 to 6.0.6, fixed in 6.0.7 |
| CVE-2023-20863 | Denial of service through a crafted SpEL expression | 5.3.0 to 5.3.26, fixed in 5.3.27 | 6.0.0 to 6.0.7, fixed in 6.0.8 |
CVE-2023-20860 matters most here, because the mismatch sits between Spring MVC and Spring Security. An application that looks correctly locked down in its security configuration can still expose paths. NVD rates it 7.5.
2024: URL parsing, ETags and static resources
| CVE | Issue | 5.3.x | 6.0.x | 6.1.x |
|---|---|---|---|---|
| CVE-2024-22243 | Open redirect or SSRF when UriComponentsBuilder parses an external URL that is then host-checked | 5.3.31 and earlier, fixed in 5.3.32 | 6.0.0 to 6.0.16, fixed in 6.0.17 | 6.1.0 to 6.1.3, fixed in 6.1.4 |
| CVE-2024-22259 | Same class as CVE-2024-22243, different input | 5.3.32 and earlier, fixed in 5.3.33 | 6.0.0 to 6.0.17, fixed in 6.0.18 | 6.1.0 to 6.1.4, fixed in 6.1.5 |
| CVE-2024-22262 | Same class again, different input | 5.3.33 and earlier, fixed in 5.3.34 | 6.0.0 to 6.0.18, fixed in 6.0.19 | 6.1.0 to 6.1.5, fixed in 6.1.6 |
| CVE-2024-38809 | Denial of service when parsing ETags from If-Match or If-None-Match headers | 5.3.37 and earlier, fixed in 5.3.38 | 6.0.0 to 6.0.22, fixed in 6.0.23 | 6.1.0 to 6.1.11, fixed in 6.1.12 |
| CVE-2024-38816 | Path traversal when WebMvc.fn or WebFlux.fn serve static resources from a FileSystemResource | 5.3.39 and earlier, fixed in 5.3.40 (commercial) | 6.0.0 to 6.0.23, fixed in 6.0.24 (commercial) | 6.1.0 to 6.1.12, fixed in 6.1.13 |
| CVE-2024-38819 | Path traversal in the functional web frameworks, a variant of CVE-2024-38816 | 5.3.40 and earlier, fixed in 5.3.41 (commercial) | 6.0.0 to 6.0.24, fixed in 6.0.25 (commercial) | 6.1.0 to 6.1.13, fixed in 6.1.14 |
| CVE-2024-38820 | DataBinder disallowedFields can be bypassed because of locale-dependent lowercasing | 5.3.40 and earlier, fixed in 5.3.41 (commercial) | 6.0.0 to 6.0.24, fixed in 6.0.25 (commercial) | 6.1.0 to 6.1.13, fixed in 6.1.14 |
The three UriComponentsBuilder CVEs are one problem found three times. Upgrading past the first fix was not enough: 5.3.32 fixed CVE-2024-22243 and was still exposed to the next two. The two path traversal CVEs differ in one detail that changes the risk: for CVE-2024-38816, Spring says Tomcat and Jetty reject the malicious requests, but its advisory for CVE-2024-38819 states that applications on Tomcat or Jetty are vulnerable.
2024 is also where the line between open source and commercial fixes appears. 5.3.x and 6.0.x left open source support in mid 2024, so from CVE-2024-38816 onward their fixes are Enterprise Support Only.
2025: data binding, path traversal and method security
| CVE | Issue | 5.3.x | 6.0.x | 6.1.x | 6.2.x |
|---|---|---|---|---|---|
| CVE-2025-22233 | Further disallowedFields bypass after the CVE-2024-38820 fix | 5.3.42 and earlier, fixed in 5.3.43 (commercial) | 6.0.0 to 6.0.27, fixed in 6.0.28 (commercial) | 6.1.0 to 6.1.19, fixed in 6.1.20 | 6.2.0 to 6.2.6, fixed in 6.2.7 |
| CVE-2025-41242 | Path traversal on Servlet containers that do not reject suspicious sequences | 5.3.43 and earlier, fixed in 5.3.44 (commercial) | Affected (the advisory lists 6.0.0 to 6.1.21 as one range); no 6.0 fix listed | Up to 6.1.21, fixed in 6.1.22 (commercial) | 6.2.0 to 6.2.9, fixed in 6.2.10 |
| CVE-2025-41249 | Annotation detection can miss security annotations on generic superclasses and interfaces used with @EnableMethodSecurity | 5.3.44 and earlier, fixed in 5.3.45 (commercial) | Not listed | 6.1.0 to 6.1.22, fixed in 6.1.23 (commercial) | 6.2.0 to 6.2.10, fixed in 6.2.11 |
| CVE-2025-41254 | STOMP over WebSocket security bypass that lets an attacker send unauthorized messages | 5.3.45 and earlier, fixed in 5.3.46 (commercial) | Affected (the advisory lists 6.0.0 to 6.1.23 as one range); no 6.0 fix listed | Up to 6.1.23, fixed in 6.1.24 (commercial) | 6.2.0 to 6.2.11, fixed in 6.2.12 |
CVE-2025-22233 is the one that trips people up. Its advisory shows 6.1.20 as an open source fix, because it shipped in May 2025, before 6.1 left open source support at the end of June. From CVE-2025-41242 in August 2025, 6.1 fixes are commercial too. For CVE-2025-41249, Spring's advisory says applications are affected only if they use @EnableMethodSecurity with security annotations on methods in generic superclasses or generic interfaces.
2026: 6.2 joins the older lines
| CVE | Issue | 5.3.x | 6.0.x | 6.1.x | 6.2.x |
|---|---|---|---|---|---|
| CVE-2026-22737 | File disclosure through script template views backed by a Java scripting engine | 5.3.46 and earlier, fixed in 5.3.47 (commercial) | Not listed | 6.1.0 to 6.1.25, fixed in 6.1.26 (commercial) | 6.2.0 to 6.2.16, fixed in 6.2.17 |
| CVE-2026-41843 | Path traversal when resolving static resources in Spring MVC and WebFlux | 5.3.48 and earlier, fixed in 5.3.49 (commercial) | Not listed | 6.1.0 to 6.1.27, fixed in 6.1.28 (commercial) | 6.2.0 to 6.2.18, fixed in 6.2.19 |
| CVE-2026-47884 | SSRF and remote code execution through XsltView with a "/**" mapping and no explicit view name | 5.3.0 to 5.3.49, fixed in 5.3.50 (commercial) | 6.0.0 to 6.0.30, fixed in 6.0.31 (commercial) | 6.1.0 to 6.1.28, fixed in 6.1.29 (commercial) | 6.2.0 to 6.2.19, fixed in 6.2.20 (commercial) |
The same advisories cover 7.0: CVE-2026-22737 is fixed in 7.0.6, CVE-2026-41843 in 7.0.8 and CVE-2026-47884 in 7.0.9, all open source. CVE-2026-47884, published in August 2026, is the first advisory in this guide where the 6.2.x fix is commercial, because 6.2 left open source support on 30 June 2026. NVD lists many more 2026 Spring Framework advisories across the same lines, and the Spring Framework support page tracks them.
What this means for each line
- 5.3.x. Open source support ended on 31 August 2024. Every fix since CVE-2024-38816 is commercial. The line runs on Java 8 and javax, which is why so many estates are still on it. See Spring Framework 5 end of life.
- 6.0.x. Open source support ended on 30 June 2024, before 5.3. Several 2025 and 2026 advisories do not list 6.0 at all, which leaves teams without a clear statement either way.
- 6.1.x. Open source support ended on 30 June 2025. Fixes up to CVE-2025-22233 are public; later ones are commercial.
- 6.2.x. Open source support ended on 30 June 2026. Fixes up to 6.2.19 are public; CVE-2026-47884 is the first commercial-only 6.2 fix.
A scanner will flag each of these lines against every later advisory, whether or not a public fix exists. The options are the same for all of them: upgrade to 7.0, buy commercial support from Broadcom, or take patched builds from another supplier.
Where OSSeva fits
OSSeva ships patched, signed Spring Framework builds for 5.3.x, 6.0.x, 6.1.x and 6.2.x, with the fixes above backported and delivered through your own Maven or Gradle repository manager. They are available now on the Patch, Assure and Operate tiers, and Assure adds a VEX statement for each CVE. See Spring continuation for how the builds are delivered, and Spring Boot 4.0 end of life for the next open source deadline in the Spring stack, on 31 December 2026.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationHashiCorp Consul End of Life: The BSL Licence, IBM Support Cycles and Your Options
September 29, 2026MigrationCloudera CDH and HDP End of Life: Dates, the ZooKeeper Underneath, and Your Options
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.