Back to blog

// OSSeva Blog

Operations

Spring Support Calendar 2026 to 2027: Every Spring Boot, Framework and Security Deadline

Randall McClure7 min read

The short answer

Spring publishes two end dates for every release line. The open source (OSS) date is when public fixes stop. The commercial date is when Broadcom stops shipping fixes to paying Spring Enterprise customers. As of 5 October 2026, the only lines with OSS support left are Spring Boot 4.0 and 4.1, Spring Framework 7.0, and Spring Security 7.0 and 7.1. Spring Boot 3.5 and Spring Framework 6.2 both left OSS support on 30 June 2026.

The next cliff is 31 December 2026. On that day Spring Boot 4.0 and Spring Security 7.0 reach OSS end, and Spring Boot 3.4 and Spring Security 6.4 reach commercial end. After that, no one at Broadcom ships fixes for Boot 3.4 at any price.

The full calendar

All dates come from the generations endpoints on api.spring.io, which drive the support pages on spring.io. "Ended" marks a date already passed on 5 October 2026.

Project and lineOSS support endsCommercial support ends
Spring Boot 2.7.x30 Jun 2023 (ended)30 Jun 2029
Spring Boot 3.0.x31 Dec 2023 (ended)31 Dec 2024 (ended)
Spring Boot 3.1.x30 Jun 2024 (ended)30 Jun 2025 (ended)
Spring Boot 3.2.x31 Dec 2024 (ended)31 Dec 2025 (ended)
Spring Boot 3.3.x30 Jun 2025 (ended)30 Jun 2026 (ended)
Spring Boot 3.4.x31 Dec 2025 (ended)31 Dec 2026
Spring Boot 3.5.x30 Jun 2026 (ended)30 Jun 2032
Spring Boot 4.0.x31 Dec 202631 Dec 2027
Spring Boot 4.1.x31 Jul 202731 Jul 2028
Spring Boot 4.2.x (due 30 Nov 2026)31 Dec 202731 Dec 2028
Spring Framework 5.3.x31 Aug 2024 (ended)30 Jun 2029
Spring Framework 6.0.x30 Jun 2024 (ended)30 Jun 2032
Spring Framework 6.1.x30 Jun 2025 (ended)30 Jun 2032
Spring Framework 6.2.x30 Jun 2026 (ended)30 Jun 2032
Spring Framework 7.0.x31 Jul 202731 Jul 2028
Spring Framework 7.1.x (due 30 Nov 2026)31 Dec 202731 Dec 2028
Spring Security 5.8.x31 Dec 2023 (ended)30 Jun 2029
Spring Security 6.0.x31 Dec 2023 (ended)31 Dec 2024 (ended)
Spring Security 6.1.x30 Jun 2024 (ended)30 Jun 2025 (ended)
Spring Security 6.2.x31 Dec 2024 (ended)31 Dec 2025 (ended)
Spring Security 6.3.x30 Jun 2025 (ended)30 Jun 2026 (ended)
Spring Security 6.4.x31 Dec 2025 (ended)31 Dec 2026
Spring Security 6.5.x30 Jun 2026 (ended)30 Jun 2032
Spring Security 7.0.x31 Dec 202631 Dec 2027
Spring Security 7.1.x31 Jul 202731 Jul 2028
Spring Security 7.2.x (due 30 Nov 2026)31 Dec 202731 Dec 2028

The "due" dates for Boot 4.2, Framework 7.1 and Security 7.2 are Spring's planned first-release dates. Boot 4.2.0-M2 and Security 7.2.0-M2 are already published as milestones, so the lines are on track, but treat the end dates as provisional until the GA release ships.

Reading the pattern

Three things stand out once the lines sit side by side.

  • OSS windows are short. A Spring Boot minor gets about 13 months of public fixes. Each new minor ships roughly six months after the last, so in practice only the two newest Boot lines are ever covered.
  • The last line of a major gets a long commercial tail. Boot 2.7 and Security 5.8, with Framework 5.3 beneath them, run commercially to 30 June 2029. Boot 3.5 and Security 6.5 run to 30 June 2032, and so do Framework 6.0, 6.1 and 6.2. Boot 3.0 to 3.4, and Security 6.0 to 6.4 alongside them, got one year of commercial support after OSS end and no more.
  • Boot and Framework do not end together. Spring Framework 7.0 keeps OSS support until 31 July 2027, seven months after Boot 4.0 loses it. Framework fixes keep coming into 2027, but Boot 4.0 will not ship new patch releases to pick them up.

The 31 December 2026 cliff

Four lines hit an end date on the same day:

  • Spring Boot 4.0: OSS end. The first Boot 4 line stops getting public patch releases. Teams that moved early to 4.0 need to be on 4.1 or 4.2 by year end to stay on free fixes. See the Spring Boot 4.0 end-of-life page for that line.
  • Spring Security 7.0: OSS end. This follows Boot 4.0, which depends on it. Security 7.1 carries OSS support to 31 July 2027.
  • Spring Boot 3.4: commercial end. Its OSS support ended a year earlier. After this date Broadcom will not ship fixes for 3.4 to anyone, including Spring Enterprise subscribers. The commercial path for a 3.x application is Boot 3.5, which runs to 2032.
  • Spring Security 6.4: commercial end. This is the Security line that ships with Boot 3.4, so it falls on the same date.

If you are planning against this date, the quickest test is to list every service by its Spring Boot minor. Anything on 3.4 or earlier, or on 4.0, has a deadline inside the next three months.

Where TrueSource fits

Broadcom announced TrueSource on 31 August 2026. It places Spring Enterprise alongside new artifact and data-engine offerings, but it did not change any of the dates above. Spring Enterprise customers get fixes for the lines that are still inside their commercial window. In practice that means Boot 2.7 and 3.5 (with Framework 5.3 and 6.x and Security 5.8 and 6.5), plus Boot 3.4 until the end of this year and the 4.x lines.

A line whose commercial date has passed does not come back by signing. Boot 3.0 to 3.3 and Security 6.0 to 6.3 are out of commercial support today. Buying TrueSource for a 3.3 estate buys you an upgrade path to 3.5, not patches for 3.3. Broadcom has not published TrueSource pricing. For the full breakdown, see Broadcom TrueSource explained.

Your options by line

  • On Boot 4.0: move to 4.1 now, or to 4.2 once it is GA. Both are minor upgrades inside the same major, and they keep you on free OSS fixes through 2027.
  • On Boot 3.5: OSS support has ended. You can buy Spring Enterprise, which covers 3.5 to 2032, use third-party support, or plan the move to Boot 4. The Spring Boot 3.5 end-of-life page covers that line.
  • On Boot 3.0 to 3.4: Broadcom's commercial support for 3.0 to 3.3 is over, and for 3.4 it ends on 31 December. Your choices are an upgrade to 3.5 or 4.x, or third-party patches for the line you run.
  • On Boot 2.7 with Framework 5.3 and Security 5.8: commercial support runs to 30 June 2029, so this line has more vendor runway than Boot 3.3. The move to Boot 3 means Java 17 and the javax to jakarta namespace change. We compare the support routes in Spring 5 support options.

OSSeva provides extended support for the Spring lines your services run today. We ship backported CVE fixes for Spring Boot 2.6 and 2.7, 3.0 to 3.5, and 4.0 and 4.1. Framework 5.2 to 7.0 and Security 5.6 to 7.1 are covered on the same terms. Coverage does not depend on Broadcom's commercial dates, so Boot 3.0 to 3.3 are covered too. See Spring Boot support for the version list.

Trackers for each project

The dates in this post are also kept on the per-project trackers, which refresh from upstream data:

Common questions

Which Spring Boot versions are still supported for free?

As of 5 October 2026, only Spring Boot 4.0 and 4.1. Spring Boot 4.0 loses OSS support on 31 December 2026, and 4.1 on 31 July 2027.

When does Spring Boot 3.5 reach end of life?

Its OSS support ended on 30 June 2026. Commercial support from Broadcom runs to 30 June 2032.

Is Spring Boot 3.4 still supported?

Only commercially, and only until 31 December 2026. OSS support ended on 31 December 2025.

Does Spring Framework 6.2 still get free fixes?

No. Spring Framework 6.2 left OSS support on 30 June 2026. Commercial support runs to 30 June 2032, the same as 6.0 and 6.1.

Tags

Spring BootSpring FrameworkSpring SecurityEnd of LifeBroadcomTrueSource

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.