End of life

Spring Security 6 end of life

Spring Security 6 is out of open source support. Its last line, 6.5, reached the end of open source support on 30 June 2026, and spring.io lists commercial support for 6.5 until 30 June 2032. The last open source release is 6.5.11, from 9 June 2026. Commercial support for 6.4 ends on 31 December 2026, and 6.0 to 6.3 have no vendor support left.

End of life
30 June 2026
Released
Nov 2022
Final release
6.5.11 (last open source release, 9 June 2026)
Successor
Spring Security 7.1

Date published by spring.io Spring Security generations. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 30 June 2026

  • Open source 6.x releases. 6.5.11 is the last; 6.4 open source support ended on 31 December 2025.
  • Open source fixes for the authentication layer. CVE-2026-41707 (DPoP proof replay), CVE-2026-47841 (WebAuthn user verification bypass) and CVE-2026-47842 (fixed IV in AesBytesEncryptor) all affect 6.5.0 to 6.5.11, and spring.io lists the 6.5.12 fix as Enterprise Support Only.
  • Vendor support of any kind for 6.0 to 6.3, whose commercial dates have passed. 6.4 follows on 31 December 2026.

What actually breaks in the upgrade

Security moves with Boot

Spring Boot 3.5 manages Spring Security 6.5, and Boot 4.1 manages Spring Security 7.1. Most applications take the version their Boot release manages, so the practical upgrade is Boot 3.5 to 4.1.

Check which 2026 advisories reach you

CVE-2026-41707 matters only if you accept DPoP-bound tokens. CVE-2026-47841 matters if you require WebAuthn user verification and use a distributed session store. CVE-2026-47842 matters if you encrypt data with AesBytesEncryptor in CBC mode, and spring.io says to check whether stored data needs re-encryption.

7.1 has its own date

Spring Security 7.1 is supported in open source to 31 July 2027. Spring Security 7.0, the line under Boot 4.0, ends on 31 December 2026, so skip it.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to Spring Security 7.1Usually by moving Spring Boot from 3.5 to 4.1.Weeks to monthsEngineering timeThe supported path, open source to 31 July 2027.
OSSeva patched Spring Security 6Signed 6.x artifacts with backported fixes for core, web, OAuth2, SAML and WebAuthn.DaysSubscriptionCloses the 2026 advisories while the Boot 4 move is tested.
Broadcom commercial supportCommercial 6.5 releases to 30 June 2032; 6.4 to 31 December 2026.ProcurementCommercial subscriptionCovers 6.5 and, for three more months, 6.4. Nothing for 6.0 to 6.3.
Stay on 6.5.11No open source fixes since June 2026.NoneZero nowThe authentication layer is the worst place to carry open advisories.

What OSSeva does for Spring Security 6

OSSeva patches this line

OSSeva ships patched, signed Spring Security 6.x artifacts, from 6.0 to 6.5, with backported fixes for the core, web, OAuth2, SAML and WebAuthn modules, delivered through your own repository manager. They are available now on the Patch, Assure and Operate tiers.

Spring Security extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library Every Spring Security version and end-of-life date

Spring Security 6: common questions

When did Spring Security 6 reach end of life?

Open source support for 6.5, the last 6.x line, ended on 30 June 2026. spring.io lists commercial support for 6.5 until 30 June 2032 and for 6.4 until 31 December 2026.

What is the last open source Spring Security 6 release?

6.5.11, released on 9 June 2026. 6.0.0 was released on 21 November 2022.

Which Spring Boot version uses Spring Security 6.5?

Spring Boot 3.5. Spring Boot 4.1 uses Spring Security 7.1.

Which CVEs affect Spring Security 6.5.11?

CVE-2026-41707, CVE-2026-47841 and CVE-2026-47842, all published by spring.io on 20 August 2026. The 6.5 fix, 6.5.12, is Enterprise Support Only.

Can I get security patches for Spring Security 6?

Yes. OSSeva ships patched, signed Spring Security 6.x artifacts on the Patch, Assure and Operate tiers.

Still running Spring Security 6?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.