Back to blog

// OSSeva Blog

Security

Spring Framework Vulnerabilities by Version: CVEs for 5.3.x, 6.0.x and 6.1.x

Randall McClure8 min read

The short answer

Every Spring Framework line before 7.0 is now outside open source support. According to spring.io, open source support ended for 6.0.x on 30 June 2024, for 5.3.x on 31 August 2024, for 6.1.x on 30 June 2025 and for 6.2.x on 30 June 2026. Spring Framework 7.0 is supported until 31 July 2027. Since those dates, Spring's advisories have kept listing fixed versions for the older lines, but marked them "Enterprise Support Only", which means the fix exists and is not published to Maven Central. The tables below show, for each notable CVE, which releases are affected and where the fix is available.

How to read the tables

  • Affected is the range from the spring.io advisory. "and earlier" means the advisory lists no lower bound for that line.
  • Fixed is the first release with the fix. "(commercial)" means the advisory marks it Enterprise Support Only.
  • Not listed means the advisory does not mention that line. It is not a statement that the line is safe.

Advisories also note that older, unsupported versions are affected. That covers 5.2.x and earlier, which this guide does not track.

2022: Spring4Shell and SpEL

CVEIssue5.3.x6.0.x
CVE-2022-22965 (Spring4Shell)Remote code execution through data binding on JDK 9 and later5.3.0 to 5.3.17, fixed in 5.3.18Not listed (6.0 was not yet released)
CVE-2022-22950Denial of service through a crafted SpEL expression5.3.0 to 5.3.16, fixed in 5.3.17Not listed (6.0 was not yet released)

CVE-2022-22965 is rated 9.8 on NVD. The published exploit needs the application to run on Tomcat as a WAR deployment, and Spring's advisory says an executable Spring Boot jar, the default, is not vulnerable to that exploit. The advisory adds that the flaw is more general and other exploit paths may exist, so the fix, not the deployment shape, is the control. 5.2.x was fixed in 5.2.20.RELEASE.

2023: request matching and more SpEL

CVEIssue5.3.x6.0.x
CVE-2023-20860Security bypass when "**" is used as a pattern with mvcRequestMatcher in Spring Security configuration5.3.25 and earlier, fixed in 5.3.266.0.0 to 6.0.6, fixed in 6.0.7
CVE-2023-20861Denial of service through a crafted SpEL expression5.3.0 to 5.3.25, fixed in 5.3.266.0.0 to 6.0.6, fixed in 6.0.7
CVE-2023-20863Denial of service through a crafted SpEL expression5.3.0 to 5.3.26, fixed in 5.3.276.0.0 to 6.0.7, fixed in 6.0.8

CVE-2023-20860 matters most here, because the mismatch sits between Spring MVC and Spring Security. An application that looks correctly locked down in its security configuration can still expose paths. NVD rates it 7.5.

2024: URL parsing, ETags and static resources

CVEIssue5.3.x6.0.x6.1.x
CVE-2024-22243Open redirect or SSRF when UriComponentsBuilder parses an external URL that is then host-checked5.3.31 and earlier, fixed in 5.3.326.0.0 to 6.0.16, fixed in 6.0.176.1.0 to 6.1.3, fixed in 6.1.4
CVE-2024-22259Same class as CVE-2024-22243, different input5.3.32 and earlier, fixed in 5.3.336.0.0 to 6.0.17, fixed in 6.0.186.1.0 to 6.1.4, fixed in 6.1.5
CVE-2024-22262Same class again, different input5.3.33 and earlier, fixed in 5.3.346.0.0 to 6.0.18, fixed in 6.0.196.1.0 to 6.1.5, fixed in 6.1.6
CVE-2024-38809Denial of service when parsing ETags from If-Match or If-None-Match headers5.3.37 and earlier, fixed in 5.3.386.0.0 to 6.0.22, fixed in 6.0.236.1.0 to 6.1.11, fixed in 6.1.12
CVE-2024-38816Path traversal when WebMvc.fn or WebFlux.fn serve static resources from a FileSystemResource5.3.39 and earlier, fixed in 5.3.40 (commercial)6.0.0 to 6.0.23, fixed in 6.0.24 (commercial)6.1.0 to 6.1.12, fixed in 6.1.13
CVE-2024-38819Path traversal in the functional web frameworks, a variant of CVE-2024-388165.3.40 and earlier, fixed in 5.3.41 (commercial)6.0.0 to 6.0.24, fixed in 6.0.25 (commercial)6.1.0 to 6.1.13, fixed in 6.1.14
CVE-2024-38820DataBinder disallowedFields can be bypassed because of locale-dependent lowercasing5.3.40 and earlier, fixed in 5.3.41 (commercial)6.0.0 to 6.0.24, fixed in 6.0.25 (commercial)6.1.0 to 6.1.13, fixed in 6.1.14

The three UriComponentsBuilder CVEs are one problem found three times. Upgrading past the first fix was not enough: 5.3.32 fixed CVE-2024-22243 and was still exposed to the next two. The two path traversal CVEs differ in one detail that changes the risk: for CVE-2024-38816, Spring says Tomcat and Jetty reject the malicious requests, but its advisory for CVE-2024-38819 states that applications on Tomcat or Jetty are vulnerable.

2024 is also where the line between open source and commercial fixes appears. 5.3.x and 6.0.x left open source support in mid 2024, so from CVE-2024-38816 onward their fixes are Enterprise Support Only.

2025: data binding, path traversal and method security

CVEIssue5.3.x6.0.x6.1.x6.2.x
CVE-2025-22233Further disallowedFields bypass after the CVE-2024-38820 fix5.3.42 and earlier, fixed in 5.3.43 (commercial)6.0.0 to 6.0.27, fixed in 6.0.28 (commercial)6.1.0 to 6.1.19, fixed in 6.1.206.2.0 to 6.2.6, fixed in 6.2.7
CVE-2025-41242Path traversal on Servlet containers that do not reject suspicious sequences5.3.43 and earlier, fixed in 5.3.44 (commercial)Affected (the advisory lists 6.0.0 to 6.1.21 as one range); no 6.0 fix listedUp to 6.1.21, fixed in 6.1.22 (commercial)6.2.0 to 6.2.9, fixed in 6.2.10
CVE-2025-41249Annotation detection can miss security annotations on generic superclasses and interfaces used with @EnableMethodSecurity5.3.44 and earlier, fixed in 5.3.45 (commercial)Not listed6.1.0 to 6.1.22, fixed in 6.1.23 (commercial)6.2.0 to 6.2.10, fixed in 6.2.11
CVE-2025-41254STOMP over WebSocket security bypass that lets an attacker send unauthorized messages5.3.45 and earlier, fixed in 5.3.46 (commercial)Affected (the advisory lists 6.0.0 to 6.1.23 as one range); no 6.0 fix listedUp to 6.1.23, fixed in 6.1.24 (commercial)6.2.0 to 6.2.11, fixed in 6.2.12

CVE-2025-22233 is the one that trips people up. Its advisory shows 6.1.20 as an open source fix, because it shipped in May 2025, before 6.1 left open source support at the end of June. From CVE-2025-41242 in August 2025, 6.1 fixes are commercial too. For CVE-2025-41249, Spring's advisory says applications are affected only if they use @EnableMethodSecurity with security annotations on methods in generic superclasses or generic interfaces.

2026: 6.2 joins the older lines

CVEIssue5.3.x6.0.x6.1.x6.2.x
CVE-2026-22737File disclosure through script template views backed by a Java scripting engine5.3.46 and earlier, fixed in 5.3.47 (commercial)Not listed6.1.0 to 6.1.25, fixed in 6.1.26 (commercial)6.2.0 to 6.2.16, fixed in 6.2.17
CVE-2026-41843Path traversal when resolving static resources in Spring MVC and WebFlux5.3.48 and earlier, fixed in 5.3.49 (commercial)Not listed6.1.0 to 6.1.27, fixed in 6.1.28 (commercial)6.2.0 to 6.2.18, fixed in 6.2.19
CVE-2026-47884SSRF and remote code execution through XsltView with a "/**" mapping and no explicit view name5.3.0 to 5.3.49, fixed in 5.3.50 (commercial)6.0.0 to 6.0.30, fixed in 6.0.31 (commercial)6.1.0 to 6.1.28, fixed in 6.1.29 (commercial)6.2.0 to 6.2.19, fixed in 6.2.20 (commercial)

The same advisories cover 7.0: CVE-2026-22737 is fixed in 7.0.6, CVE-2026-41843 in 7.0.8 and CVE-2026-47884 in 7.0.9, all open source. CVE-2026-47884, published in August 2026, is the first advisory in this guide where the 6.2.x fix is commercial, because 6.2 left open source support on 30 June 2026. NVD lists many more 2026 Spring Framework advisories across the same lines, and the Spring Framework support page tracks them.

What this means for each line

  • 5.3.x. Open source support ended on 31 August 2024. Every fix since CVE-2024-38816 is commercial. The line runs on Java 8 and javax, which is why so many estates are still on it. See Spring Framework 5 end of life.
  • 6.0.x. Open source support ended on 30 June 2024, before 5.3. Several 2025 and 2026 advisories do not list 6.0 at all, which leaves teams without a clear statement either way.
  • 6.1.x. Open source support ended on 30 June 2025. Fixes up to CVE-2025-22233 are public; later ones are commercial.
  • 6.2.x. Open source support ended on 30 June 2026. Fixes up to 6.2.19 are public; CVE-2026-47884 is the first commercial-only 6.2 fix.

A scanner will flag each of these lines against every later advisory, whether or not a public fix exists. The options are the same for all of them: upgrade to 7.0, buy commercial support from Broadcom, or take patched builds from another supplier.

Where OSSeva fits

OSSeva ships patched, signed Spring Framework builds for 5.3.x, 6.0.x, 6.1.x and 6.2.x, with the fixes above backported and delivered through your own Maven or Gradle repository manager. They are available now on the Patch, Assure and Operate tiers, and Assure adds a VEX statement for each CVE. See Spring continuation for how the builds are delivered, and Spring Boot 4.0 end of life for the next open source deadline in the Spring stack, on 31 December 2026.

Tags

Spring FrameworkCVESpring4ShellCVE-2022-22965End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.