Spring Framework 6.1.6, 6.0.19 and 5.3.34 Available Now Including Fixes for CVE-2024-22262
On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Framework 6.1.6
, 6.0.19
and 5.3.34
are available now:
- Spring Framework
6.1.6
ships with 41 fixes and documentation improvements. This version will be shipped with Spring Boot 3.2.5, to be released next week. - Spring Framework
6.0.19
ships with 14 fixes and documentation improvements. This version will be shipped with Spring Boot 3.1.11, to be released next week. - Spring Framework
5.3.34
ships with 10 fixes and documentation improvements.
The releases address CVE-2024-22262 for "URL Parsing with Host Validation (3rd report)". Important CVEs on popular projects, like the original CVE-2024-22243, often get attention from the security community. We received many reports and helpful feedback about new attack variants over the last weeks. The security of Spring applications is…