Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESBROADCOMVERIFIED

PUBLISHER UPDATE · SPRING-FRAMEWORK-7.0.8

SPRING-FRAMEWORK-7.0.8 release notes and known issues

v7.0.8

Scope: Spring Framework. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

⚠️ Security Fixes This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs: CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module" CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux" CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux" CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux" CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux" CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux" CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux" CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils" CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags" CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher" CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions" CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL" CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions" CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux" CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder" CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters" ⭐ New Features Include zone ID in CronTrigger's equals/hashCode implementations #36871 Expose ClassLoader from DefaultDeserializer #36833 Use immutable map for SEPARATORS static field in DefaultPathContainer #36821 Track operations during SpEL expression evaluation #36801 Ensure getters have non-void return types in SpEL #36800 Avoid too many character access attempts in AntPathMatcher #36799 Refine default view name resolution #36793 Refine Jackson JMS converters #36791 Improve ABNF rule checks in RfcUriParser #36787 Restrict SpringVersion.getVersion() to "major.minor.patch" format #36785 Runtime compatibility with JPA 4.0 M4 and corresponding Hibernate 8.0 snapshots #36784 Allow specifying the charset to use in ExchangeFilterFunctions#basicAuthentication #36777 Use CollectionUtils to initialize HashMap in DefaultUriBuilderFactory #36763 Improve error messages in SpEL #36756 Improve pattern caching in SpEL #36755 Avoid ResolvableType#forType contention for implicit cache cleanup #36745 Switch to JdkIdGenerator for WebSocket Sessions #36740 Detect custom deserialized NullValue instances in AbstractValueAdaptingCache #36727 LiteWebJarsResourceResolver does not resolve directories #36726 Warn against unsafe static resource locations in MVC and WebFlux #36692 Consistent compatibility with Woodstox as an alternative to Xerces #36682 Improve principal checks for SockJS session #36681 Set host header consistently in STOMP relay CONNECT frames #36673 Support Micrometer context propagation in Kotlin Flow #36667 Reliable detection of broadcast messages in UserDestinationMessageHandler #36662 🐞 Bug Fixes Concurrency issue against shared cookie field in CookieLocaleResolver#setLocaleContext #36869 Server Sent Event does not support multi-line comments #36866 CronExpression skips days on midnight DST gap #36865 Regression in 6.2.0+: ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36835 Preserve generic type info in awaitEntity() #36834 Bean Background Bootstrap and Lazy Init #36844 Back-off for DefaultMessageListenerContainer with OracleAQ has changed and is very short in SpringBoot 4 #36809 Character outside of permitted range in Content Disposition #36805 Fix JSP tag processing #36797 Fix script processing capabilities #36795 Jaxb2XmlEncoder exclusivity prevents JacksonXmlEncoder usage and hinders POJO serialization #36776 Jac

Improvements and security content

  • ⚠️ Security Fixes This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs: CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module" CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux" CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux" CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux" CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux" CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux" CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux" CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils" CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags" CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher" CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions" CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL" CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions" CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux" CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder" CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters" ⭐ New Features Include zone ID in CronTrigger's equals/hashCode implementations #36871 Expose ClassLoader from DefaultDeserializer #36833 Use immutable map for SEPARATORS static field in DefaultPathContainer #36821 Track operations during SpEL expression evaluation #36801 Ensure getters have non-void return types in SpEL #36800 Avoid too many character access attempts in AntPathMatcher #36799 Refine default view name resolution #36793 Refine Jackson JMS converters #36791 Improve ABNF rule checks in RfcUriParser #36787 Restrict SpringVersion.getVersion() to "major.minor.patch" format #36785 Runtime compatibility with JPA 4.0 M4 and corresponding Hibernate 8.0 snapshots #36784 Allow specifying the charset to use in ExchangeFilterFunctions#basicAuthentication #36777 Use CollectionUtils to initialize HashMap in DefaultUriBuilderFactory #36763 Improve error messages in SpEL #36756 Improve pattern caching in SpEL #36755 Avoid ResolvableType#forType contention for implicit cache cleanup #36745 Switch to JdkIdGenerator for WebSocket Sessions #36740 Detect custom deserialized NullValue instances in AbstractValueAdaptingCache #36727 LiteWebJarsResourceResolver does not resolve directories #36726 Warn against unsafe static resource locations in MVC and WebFlux #36692 Consistent compatibility with Woodstox as an alternative to Xerces #36682 Improve principal checks for SockJS session #36681 Set host header consistently in STOMP relay CONNECT frames #36673 Support Micrometer context propagation in Kotlin Flow #36667 Reliable detection of broadcast messages in UserDestinationMessageHandler #36662 🐞 Bug Fixes Concurrency issue against shared cookie field in CookieLocaleResolver#setLocaleContext #36869 Server Sent Event does not support multi-line comments #36866 CronExpression skips days on midnight DST gap #36865 Regression in 6.2.0+: ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36835 Preserve generic type info in awaitEntity() #36834 Bean Background Bootstrap and Lazy Init #36844 Back-off for DefaultMessageListenerContainer with OracleAQ has changed and is very short in SpringBoot 4 #36809 Character outside of permitted range in Content Disposition #36805 Fix JSP tag processing #36797 Fix script processing capabilities #36795 Jaxb2XmlEncoder exclusivity prevents JacksonXmlEncoder usage and hinders POJO serialization #36776 Jac

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Spring Framework

Affected versions

  • 7.0.8
  • 4.0
  • 8.0
  • 6.2.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence