Spring Security 6 end of life
Spring Security 6 is out of open source support. Its last line, 6.5, reached the end of open source support on 30 June 2026, and spring.io lists commercial support for 6.5 until 30 June 2032. The last open source release is 6.5.11, from 9 June 2026. Commercial support for 6.4 ends on 31 December 2026, and 6.0 to 6.3 have no vendor support left.
- End of life
- 30 June 2026
- Released
- Nov 2022
- Final release
- 6.5.11 (last open source release, 9 June 2026)
- Successor
- Spring Security 7.1
Date published by spring.io Spring Security generations. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 30 June 2026
- Open source 6.x releases. 6.5.11 is the last; 6.4 open source support ended on 31 December 2025.
- Open source fixes for the authentication layer. CVE-2026-41707 (DPoP proof replay), CVE-2026-47841 (WebAuthn user verification bypass) and CVE-2026-47842 (fixed IV in AesBytesEncryptor) all affect 6.5.0 to 6.5.11, and spring.io lists the 6.5.12 fix as Enterprise Support Only.
- Vendor support of any kind for 6.0 to 6.3, whose commercial dates have passed. 6.4 follows on 31 December 2026.
What actually breaks in the upgrade
Security moves with Boot
Spring Boot 3.5 manages Spring Security 6.5, and Boot 4.1 manages Spring Security 7.1. Most applications take the version their Boot release manages, so the practical upgrade is Boot 3.5 to 4.1.
Check which 2026 advisories reach you
CVE-2026-41707 matters only if you accept DPoP-bound tokens. CVE-2026-47841 matters if you require WebAuthn user verification and use a distributed session store. CVE-2026-47842 matters if you encrypt data with AesBytesEncryptor in CBC mode, and spring.io says to check whether stored data needs re-encryption.
7.1 has its own date
Spring Security 7.1 is supported in open source to 31 July 2027. Spring Security 7.0, the line under Boot 4.0, ends on 31 December 2026, so skip it.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Spring Security 7.1 | Usually by moving Spring Boot from 3.5 to 4.1. | Weeks to months | Engineering time | The supported path, open source to 31 July 2027. |
| OSSeva patched Spring Security 6 | Signed 6.x artifacts with backported fixes for core, web, OAuth2, SAML and WebAuthn. | Days | Subscription | Closes the 2026 advisories while the Boot 4 move is tested. |
| Broadcom commercial support | Commercial 6.5 releases to 30 June 2032; 6.4 to 31 December 2026. | Procurement | Commercial subscription | Covers 6.5 and, for three more months, 6.4. Nothing for 6.0 to 6.3. |
| Stay on 6.5.11 | No open source fixes since June 2026. | None | Zero now | The authentication layer is the worst place to carry open advisories. |
What OSSeva does for Spring Security 6
OSSeva patches this line
OSSeva ships patched, signed Spring Security 6.x artifacts, from 6.0 to 6.5, with backported fixes for the core, web, OAuth2, SAML and WebAuthn modules, delivered through your own repository manager. They are available now on the Patch, Assure and Operate tiers.
Spring Security extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Spring Security 6: common questions
When did Spring Security 6 reach end of life?
Open source support for 6.5, the last 6.x line, ended on 30 June 2026. spring.io lists commercial support for 6.5 until 30 June 2032 and for 6.4 until 31 December 2026.
What is the last open source Spring Security 6 release?
6.5.11, released on 9 June 2026. 6.0.0 was released on 21 November 2022.
Which Spring Boot version uses Spring Security 6.5?
Spring Boot 3.5. Spring Boot 4.1 uses Spring Security 7.1.
Which CVEs affect Spring Security 6.5.11?
CVE-2026-41707, CVE-2026-47841 and CVE-2026-47842, all published by spring.io on 20 August 2026. The 6.5 fix, 6.5.12, is Enterprise Support Only.
Can I get security patches for Spring Security 6?
Yes. OSSeva ships patched, signed Spring Security 6.x artifacts on the Patch, Assure and Operate tiers.
Still running Spring Security 6?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.