v4.1.0
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · SPRING-BOOT-4.1.0
v4.1.0
Scope: Spring Boot. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Full release notes for Spring Boot 4.1 are available on the wiki. ⭐ New Features Add public constructor to InvalidConfigurationPropertyValueException that accepts a cause #50211 Reduce memory consumption when repeatedly calling WritableJson.toByteArray #49428 🐞 Bug Fixes MailSender auto-configuration does not enable hostname verification #50747 Artemis auto-configuration uses a predictable default location for the embedded broker's data #50745 Embedded LDAP SSL should not be enabled when its bundle is empty #50700 InetAddressFilter.externalAddresses does not exclude special purpose addresses from RFC 6890 #50668 NullPointerException in reactor-netty SniProvider and unmapped SSL bundle with RSocket #50645 SSL should not be enabled when a SSL bundle is overridden to an empty string #50635 Test auto-configuration no longer integrates Spring Security with HtmlUnitDriver #50633 Configuration property metadata includes incorrect class references #50632 Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50618 RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50612 NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50610 SpringJtaPlatform should have been deprecated since 4.1.0-M3 #50592 Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50510 ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50417 Created StackTracePrinter instances have no access to the Environment #50414 MappingsEndpoint reports the context's own ID as parentId when a parent exists #50412 Buildpack module does not validate long-to-int casts #50410 Gradle gRPC support fails if protobuf-java dependency is used instead of protobuf-java-util #50405 GraphQL WebSocket support does not configure allowed origins #50394 Spring Boot Loader Does Not Support RSA and EC Signed Jars #50298 Meter registries are not removed from the global registry when the context is closed #50287 DataSourceBuilder cannot derive a DataSource from a lazy connection proxy #50271 Nullable annotations from AbstractErrorController.getErrorAttributes are not aligned with implementation #50266 Bean definitions can be added with an initializer before setAllowBeanDefinitionOverriding is called #50264 EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50261 Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50258 ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50234 NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50228 Missing dependency management for spring-boot-web-server-test #50224 Spring Batch support for MongoDB modules are not included in dependency management #50223 Apply HTML escaping to timestamp attribute in Whitelabel error page #50216 GrpcServerHealthScheduler is not started in servlet environments #50209 Setting server.servlet.session.cookie.partitioned=true has no effect when using Tomcat #50204 📔 Documentation Fix reference to Gradle documentation for module replacement #50647 Document SSL reloading with Let's Encrypt #50630 Remove the use of Optional from Data Neo4j repository examples #50622 Fix typos in documentation #50620 Clarify dependency requirement for Bean Validation support #50614 Document Java 25 requirement for AOT cache #50485 Add links for Java CAS Client Spring Boot Starter #50285 Document known testcontainers lifecycle issues #50220 Document adding multiple connectors for Jetty #50218 Polish InvalidConfigurationPropertyValueException constructor javadoc #50214 Fix typo in Spring Security OAuth2 client registration documentation #50199 🔨 Dependency Upgrades Upgrade to ActiveMQ
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source