Approaching92 days from today

Spring Security 7.0 end of life

Spring Security 7.0 reaches the end of open source support on 31 December 2026, the same day as Spring Boot 4.0, which manages it. spring.io lists commercial support until 31 December 2027. 7.0.0 shipped on 17 November 2025 and the latest release is 7.0.7. Spring Security 7.1 is supported to 31 July 2027. OSSeva ships patched 7.0 artifacts after the date.

End of life
31 December 2026
Released
Nov 2025
Final release
7.0.7 (latest, 20 August 2026)
Successor
Spring Security 7.1

Date published by Spring Security support policy. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 31 December 2026

  • Open source 7.0.x releases. After 31 December 2026, 7.0 fixes ship to commercial customers only.
  • Fixes for the authentication and authorization layer. 7.0 has already needed several in 2026, such as CVE-2026-22754, an authorization bypass fixed in 7.0.5, and CVE-2026-47841, a WebAuthn user verification bypass fixed in 7.0.7.
  • The Spring Boot line that manages it. Spring Boot 4.0 ends on the same day.

What actually breaks in the upgrade

Security moves with Boot

spring.io pairs Spring Security 7.0 with Spring Boot 4.0 and 7.1 with Spring Boot 4.1. Most applications take the Security version their Boot release manages, so the practical upgrade is Boot 4.0 to 4.1, which brings Security 7.1 with it.

Check the 2026 fixes before you move

Applications on 7.0.0 to 7.0.4 that declare servlet-path on intercept-url in XML configuration are exposed to CVE-2026-22754. Applications that use WebAuthn with a distributed session store are exposed to CVE-2026-47841 on anything before 7.0.7. Update to 7.0.7 now, whatever the longer plan is.

7.1 has its own date

Spring Security 7.1 is supported in open source to 31 July 2027, and spring.io lists 7.2 with a first release on 30 November 2026. Plan the next move while doing this one.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to Spring Security 7.1Usually done by moving Spring Boot from 4.0 to 4.1.Days to weeksEngineering timeThe supported path, open source to 31 July 2027.
OSSeva patched Spring Security 7.0Signed 7.0 artifacts with backported fixes after 31 December 2026.DaysSubscriptionFor applications whose authentication setup needs longer testing than the date allows.
Broadcom commercial supportCommercial 7.0 releases, listed to 31 December 2027.ProcurementCommercial subscriptionA year of runway, on Broadcom's terms.
Stay on 7.0.x unpatchedNo open source fixes after 31 December 2026.NoneZero nowThe authentication layer is the worst place to carry open advisories.

What OSSeva does for Spring Security 7.0

OSSeva patches this line

OSSeva ships patched, signed Spring Security 7.0 artifacts, with backported fixes for the core, web, OAuth2, SAML and WebAuthn modules, delivered through your own repository manager. Coverage continues after 31 December 2026 on the Patch, Assure and Operate tiers.

Spring Security extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A runtime, framework or broker with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library

Spring Security 7.0: common questions

When does Spring Security 7.0 reach end of life?

Open source support ends on 31 December 2026. spring.io lists commercial support until 31 December 2027.

Which Spring Boot version uses Spring Security 7.0?

Spring Boot 4.0. spring.io pairs Spring Security 7.1 with Spring Boot 4.1.

What is the latest Spring Security 7.0 release?

7.0.7, released on 20 August 2026. 7.0.0 was released on 17 November 2025.

Which CVEs affect Spring Security 7.0?

Several have been fixed on the line in 2026, including CVE-2026-22754 (7.0.0 to 7.0.4, fixed in 7.0.5) and CVE-2026-47841 (7.0.0 to 7.0.6, fixed in 7.0.7). Advisories published after 31 December 2026 will not get open source 7.0 releases.

Can I get security patches for Spring Security 7.0 after 2026?

Yes. OSSeva ships patched, signed Spring Security 7.0 artifacts on the Patch, Assure and Operate tiers.

Still running Spring Security 7.0?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.