Spring Framework 6.0.7 and 5.3.26 fix cve-2023-20860 and cve-2023-20861

Releases | Brian Clozel | March 20, 2023 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that the Spring Framework 6.0.7 and 5.3.26 versions are available now.

Spring Framework 6.0.7 ships with 28 fixes and documentation improvements, including 2 fixes for regressions. Spring Framework 5.3.26 ships with 40 fixes and documentation improvements.

Those versions fix the following CVEs:

Those versions will be shipped with Spring Boot 3.0.5 and 2.7.10, to be released Thursday. In the meantime, you can update your existing Spring Boot application to pick up the latest Framework version.

For Gradle builds in build.gradle:

ext['spring-framework.version'] = '6.0.7'

Or for Maven builds in pom.xml:

<properties>
  <spring-framework.version>6.0.7</spring-framework.version>
</properties>

Project Page | GitHub | Issues | Documentation

Get the Spring newsletter

Thank you for your interest. Someone will get back to you shortly.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring Runtime offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all