Spring Boot 4.0 end of life
Spring Boot 4.0 reaches the end of open source support on 31 December 2026, and spring.io lists commercial support until 31 December 2027. 4.0.0 shipped on 20 November 2025 and the latest release is 4.0.8. Spring Boot 4.1, released in June 2026, is supported to 31 July 2027 and stays on Spring Framework 7.0. OSSeva ships patched 4.0 artifacts after the date.
- End of life
- 31 December 2026
- Released
- Nov 2025
- Final release
- 4.0.8 (latest, 21 August 2026)
- Successor
- Spring Boot 4.1
Date published by Spring Boot support policy. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 31 December 2026
- Open source 4.0.x releases. After 31 December 2026, 4.0 fixes ship to commercial customers only.
- Fixes in Spring Boot's own code: auto-configuration, Actuator and the starters. In 2026 these included CVE-2026-40976, where default web security could be ineffective, fixed in 4.0.6.
- Open source releases of Spring Security 7.0, which ends on the same day. Spring Framework 7.0, underneath both, continues to 31 July 2027.
What actually breaks in the upgrade
4.1 is a minor upgrade on the same Framework
spring.io pairs both Spring Boot 4.0 and 4.1 with Spring Framework 7.0, so the move to 4.1 does not change the core framework generation. It does change Spring Security, from 7.0 to 7.1, and the managed versions of other dependencies.
Deprecations are removed in 4.1
The 4.1 release notes remove the classes, methods and properties deprecated in 4.0. Apache Derby support is gone, the layertools jar mode is replaced by tools, and Maven's -DskipTests no longer skips AOT processing. Build with deprecation warnings on 4.0 before upgrading.
Plan for 4.2 as well
spring.io lists Spring Boot 4.2 with a first release on 30 November 2026 and open source support to 31 December 2027. A team that upgrades to 4.1 now has until 31 July 2027 before the same decision comes back.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Spring Boot 4.1 | Remove 4.0 deprecations, move to Spring Security 7.1, retest. | Days to weeks | Engineering time | The supported path, open source to 31 July 2027. |
| OSSeva patched Spring Boot 4.0 | Signed 4.0 artifacts with backported fixes for Boot and Spring Security 7.0. | Days | Subscription | For applications that cannot be upgraded and retested before 31 December 2026. |
| Broadcom commercial support | Commercial 4.0 releases, listed to 31 December 2027. | Procurement | Commercial subscription | A year of runway, on Broadcom's terms. |
| Stay on 4.0.x unpatched | No open source fixes after 31 December 2026. | None | Zero now | Actuator and default security have both had fixes this year. Hard to defend for public services. |
What OSSeva does for Spring Boot 4.0
OSSeva patches this line
OSSeva ships patched, signed Spring Boot 4.0 artifacts, with backported fixes for Spring Boot and the Spring Security 7.0 line it manages, delivered through your own Maven or Gradle repository manager. Coverage continues after 31 December 2026 on the Patch, Assure and Operate tiers.
Spring Boot extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A runtime, framework or broker with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Spring Boot 4.0: common questions
When does Spring Boot 4.0 reach end of life?
Open source support ends on 31 December 2026. spring.io lists commercial support until 31 December 2027.
What is the latest Spring Boot 4.0 release?
4.0.8, released on 21 August 2026. 4.0.0 was released on 20 November 2025.
Does Spring Boot 4.1 need a new Spring Framework version?
No. spring.io pairs both 4.0 and 4.1 with Spring Framework 7.0, which has open source support until 31 July 2027.
Which CVEs were fixed in Spring Boot 4.0?
CVE-2026-40976, where default web security could be ineffective in some Actuator setups, and CVE-2026-40971, missing hostname verification in RabbitMQ SSL bundle connections. Both affect 4.0.0 to 4.0.5 and are fixed in 4.0.6.
Can I get security patches for Spring Boot 4.0 after 2026?
Yes. OSSeva ships patched, signed Spring Boot 4.0 artifacts on the Patch, Assure and Operate tiers.
Still running Spring Boot 4.0?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.