v7.0.9
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · SPRING-FRAMEWORK-7.0.9
v7.0.9
Scope: Spring Framework. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
⚠️ Attention Required In Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090 In Spring Framework 7.0.9, SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #37035 ⭐ New Features Ignore an empty port value in URI parsing #37117 Avoid retaining class files in annotation metadata #37112 Add @Nullable annotations when treating Map.remove() as returning @Nullable #37067 Revisit SSE view fragments handling #37061 Check list index after auto-grow in AbstractNestablePropertyAccessor #37036 Disable SpEL expression compilation by default in SimpleEvaluationContext #37035 Limit result size of BigDecimal / BigInteger power operations in SpEL #37034 Refactor redirect handling in UrlHandlerFilter #37030 Revise stylesheet source handling in XsltView #37029 Revise view name handling in UrlFilenameViewController #37027 Handle pre-flight requests in functional endpoint setup without DispatcherHandler #37024 Improve WebSocket handshake error logging #37023 Fix missing nullability in JdbcTemplate.batchUpdate #37012 Timeout property in RetryPolicy does not have a default constant #36983 Write native configuration files as UTF-8 #36972 DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #36966 Perform nextKey within synchronization for SQLite as well #36959 Add support for custom ObjectInputFilter on DefaultDeserializer #36958 Revise resource bundle caching for common locales #36957 Improve nullability for getSession(*) in MockHttpServletRequest #36926 Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #36925 Improve ambiguous match check on preflight request #36903 Improve Groovy markup template loading #36902 Improve request path handling on a Reactor Netty server #36893 Improve JettyWebSocketSession error handling #36891 🐞 Bug Fixes EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #37085 MetadataReader fails to read byte[] array from annotation #37083 Ensure parsing/tostring symmetry in ContentDisposition #37064 Character outside of permitted range in Content Disposition #37062 Release Jackson BufferRecycler to its pool in encoders #37059 Ensure consistent error escaping #37055 Refine template name processing #37054 Reset TwoByteMatcher partial match on mismatching byte #37053 Refactor async XML parsing limit checks #37031 Fix part constraint checks in PartEventHttpMessageReader #37028 Fix buffer leak in RSocket SETUP frame handling #37026 Ensure correct Jetty core response cookie handling #37025 Align domainToAscii with current WhatWG spec #37018 Ensure consistent ButtonTag value attribute processing #37017 SpEL's InlineList is cached as a mutable list in compiled mode #37001 Write native configuration
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source