Spring Security 5.8 end of life
Spring Security 5.8 reached the end of open source support on 31 December 2023. The last release on Maven Central is 5.8.16, from November 2024. Broadcom's commercial support for 5.8 runs until 30 June 2029, but its releases are available only to subscribers. Spring Security 5.8 is the bridge release for moving to 6.x.
- End of life
- 31 December 2023
- Released
- Nov 2022
- Final release
- 5.8.16 (last public release, November 2024)
- Successor
- Spring Security 6.x with Spring Boot 3
Date published by Spring Security support timeline (spring.io). We do not publish a lifecycle date we cannot source.
What actually stops on 31 December 2023
- Public releases of Spring Security 5.8. 5.8.16 is the last one on Maven Central.
- Public fixes for new advisories affecting authentication and authorisation in 5.x applications.
- Compatibility work with newer Spring Framework and Spring Boot lines, which require Spring Security 6.
What actually breaks in the upgrade
5.8 exists to make 6.0 easier
Spring Security 5.8 added the 6.0 defaults and deprecations as opt-in settings, so applications can adopt them on 5.8 before switching. Teams that stayed on 5.7 or earlier miss that stepping stone.
Security 6 moves with the whole Spring stack
Spring Security 6 requires Spring Framework 6 and Spring Boot 3, which means Java 17 and the javax to jakarta namespace change. The security upgrade cannot be done on its own.
Configuration style changes
WebSecurityConfigurerAdapter is gone in 6.x. Configuration moves to SecurityFilterChain beans and the lambda DSL, which touches every application's security configuration class.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Spring Security 6 | Together with Spring Framework 6 and Spring Boot 3. | Weeks to quarters | Engineering time | The destination; plan it with the jakarta migration. |
| Broadcom commercial support | Subscriber-only 5.8 releases until June 2029. | Procurement | Commercial subscription | Covers 5.8 for Tanzu Spring customers. |
| Third-party extended support | Backported fixes for Spring Security 5.x in step with Framework 5.3 and Boot 2.7. | Days | Subscription | For applications that cannot move to the Spring 6 stack yet. |
What OSSeva does for Spring Security 5.8
OSSeva patches this line
OSSeva patches Spring Security 5.x in step with the Spring Framework 5.3 and Spring Boot 2.7 lines it is pinned to.
Spring Security extended supportWhat your auditor will say
Requirement 6.3.3. The authentication layer of a cardholder-data application is squarely in scope.
CC6.1 and CC7.1. Unpatched authentication and authorisation code is an access-control finding as well as a vulnerability-management one.
Spring Security 5.8: common questions
When did Spring Security 5.8 reach end of life?
Open source support ended on 31 December 2023. Commercial support from Broadcom continues until 30 June 2029 for subscribers.
What was the last public Spring Security 5.8 release?
5.8.16, published to Maven Central in November 2024. Later 5.8 releases are commercial only.
Can I upgrade Spring Security 5.8 to 6 without upgrading Spring Boot?
No. Spring Security 6 requires Spring Framework 6 and Spring Boot 3, so the upgrade moves the whole stack to Java 17 and the jakarta namespace.
Still running Spring Security 5.8?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.