Spring Security 7.0 end of life
Spring Security 7.0 reaches the end of open source support on 31 December 2026, the same day as Spring Boot 4.0, which manages it. spring.io lists commercial support until 31 December 2027. 7.0.0 shipped on 17 November 2025 and the latest release is 7.0.7. Spring Security 7.1 is supported to 31 July 2027. OSSeva ships patched 7.0 artifacts after the date.
- End of life
- 31 December 2026
- Released
- Nov 2025
- Final release
- 7.0.7 (latest, 20 August 2026)
- Successor
- Spring Security 7.1
Date published by Spring Security support policy. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 31 December 2026
- Open source 7.0.x releases. After 31 December 2026, 7.0 fixes ship to commercial customers only.
- Fixes for the authentication and authorization layer. 7.0 has already needed several in 2026, such as CVE-2026-22754, an authorization bypass fixed in 7.0.5, and CVE-2026-47841, a WebAuthn user verification bypass fixed in 7.0.7.
- The Spring Boot line that manages it. Spring Boot 4.0 ends on the same day.
What actually breaks in the upgrade
Security moves with Boot
spring.io pairs Spring Security 7.0 with Spring Boot 4.0 and 7.1 with Spring Boot 4.1. Most applications take the Security version their Boot release manages, so the practical upgrade is Boot 4.0 to 4.1, which brings Security 7.1 with it.
Check the 2026 fixes before you move
Applications on 7.0.0 to 7.0.4 that declare servlet-path on intercept-url in XML configuration are exposed to CVE-2026-22754. Applications that use WebAuthn with a distributed session store are exposed to CVE-2026-47841 on anything before 7.0.7. Update to 7.0.7 now, whatever the longer plan is.
7.1 has its own date
Spring Security 7.1 is supported in open source to 31 July 2027, and spring.io lists 7.2 with a first release on 30 November 2026. Plan the next move while doing this one.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to Spring Security 7.1 | Usually done by moving Spring Boot from 4.0 to 4.1. | Days to weeks | Engineering time | The supported path, open source to 31 July 2027. |
| OSSeva patched Spring Security 7.0 | Signed 7.0 artifacts with backported fixes after 31 December 2026. | Days | Subscription | For applications whose authentication setup needs longer testing than the date allows. |
| Broadcom commercial support | Commercial 7.0 releases, listed to 31 December 2027. | Procurement | Commercial subscription | A year of runway, on Broadcom's terms. |
| Stay on 7.0.x unpatched | No open source fixes after 31 December 2026. | None | Zero now | The authentication layer is the worst place to carry open advisories. |
What OSSeva does for Spring Security 7.0
OSSeva patches this line
OSSeva ships patched, signed Spring Security 7.0 artifacts, with backported fixes for the core, web, OAuth2, SAML and WebAuthn modules, delivered through your own repository manager. Coverage continues after 31 December 2026 on the Patch, Assure and Operate tiers.
Spring Security extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A runtime, framework or broker with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
Spring Security 7.0: common questions
When does Spring Security 7.0 reach end of life?
Open source support ends on 31 December 2026. spring.io lists commercial support until 31 December 2027.
Which Spring Boot version uses Spring Security 7.0?
Spring Boot 4.0. spring.io pairs Spring Security 7.1 with Spring Boot 4.1.
What is the latest Spring Security 7.0 release?
7.0.7, released on 20 August 2026. 7.0.0 was released on 17 November 2025.
Which CVEs affect Spring Security 7.0?
Several have been fixed on the line in 2026, including CVE-2026-22754 (7.0.0 to 7.0.4, fixed in 7.0.5) and CVE-2026-47841 (7.0.0 to 7.0.6, fixed in 7.0.7). Advisories published after 31 December 2026 will not get open source 7.0 releases.
Can I get security patches for Spring Security 7.0 after 2026?
Yes. OSSeva ships patched, signed Spring Security 7.0 artifacts on the Patch, Assure and Operate tiers.
Still running Spring Security 7.0?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.