in Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090
This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs:
CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module"
CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux"
CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux"
CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux"
CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux"
CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux"
CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux"
CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils"
CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags"
CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher"
CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions"
CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL"
CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions"
CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux"
CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder"
CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters"
⭐ New Features
Include zone ID in CronTrigger's equals/hashCode implementations #36871
Expose ClassLoader from DefaultDeserializer #36833
Use immutable map for SEPARATORS static field in DefaultPathContainer #36821
Track operations during SpEL expression evaluation #36801
Ensure getters have non-void return types in SpEL #36800
Avoid too many character access attempts in AntPathMatcher #36799
Avoid ResolvableType#forType contention for implicit cache cleanup #36745
Switch to JdkIdGenerator for WebSocket Sessions #36740
Detect custom deserialized NullValue instances in AbstractValueAdaptingCache #36727
LiteWebJarsResourceResolver does not resolve directories #36726
Warn against unsafe static resource locations in MVC and WebFlux #36692
Consistent compatibility with Woodstox as an alternative to Xerces #36682
Improve principal checks for SockJS session #36681
Set host header consistently in STOMP relay CONNECT frames #36673
Support Micrometer context propagation in Kotlin Flow #36667
Reliable detection of broadcast messages in UserDestinationMessageHandler #36662
🐞 Bug Fixes
Concurrency issue against shared cookie field in CookieLocaleResolver#setLocaleContext #36869
Server Sent Event does not support multi-line comments #36866
CronExpression skips days on midnight DST gap #36865
Regression in 6.2.0+: ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36835
Preserve generic type info in awaitEntity() #36834
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Release Notes
spring-projects/spring-framework (org.springframework:spring-web)v7.0.9
⚠️ Attention Required
⭐ New Features
🐞 Bug Fixes
📔 Documentation
❤️ Contributors
Thank you to all the contributors who worked on this release:
@ZaMan0806, @alexisgra, @alshain, @gianmarcoschifone, @junhyeong9812, @msridhar, @perovic, @quaff, and @samueldlightfoot
v7.0.8
⚠️ Security Fixes
This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs:
⭐ New Features
🐞 Bug Fixes
📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@0AndWild, @Dennis-Mircea, @cookie-meringue, @daguimu, @dmitrysulman, @kilink, @kzander91, @leestana01, @mguiking, @quaff, @seonwooj0810, @sgerke-1L, @shenjianeng, @tianhaocui, @wushiyuanmaimob, and @zmovo
v7.0.7
⭐ New Features
🐞 Bug Fixes
📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Mohak-Nagaraju, @Sineaggi, @T45K, @angry-2k, @bebeis, @cookie-meringue, @dmitrysulman, @elgunshukurov, @itsmevichu, @junhyung8795, @msridhar, @nameearly, @tobifasc, and @xxxxxxjun
v7.0.6
⚠️ Attention Required
⭐ New Features
🐞 Bug Fixes
📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@AgilAghamirzayev, @aavoronin93, @cetf9h, @froggy0m0, @gbouwen, @husseinvr97, @jisub-dev, @ngocnhan-tran1996, @siom79, and @xxxxxxjun
v7.0.5
⚠️ Attention Required
⭐ New Features
🐞 Bug Fixes
📔 Documentation
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Niravil and @TAKETODAY
v7.0.4
⭐ New Features
🐞 Bug Fixes
📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Ivarz, @catturtle123, @chschu, @deejay1, @dingqianwen, @dungdm93, @furaizi, @izeye, @kchung1995, @kilink, @msridhar, @ngocnhan-tran1996, @pgoslatara, @philwebb, @pisek, and @shub-est
v7.0.3
⚠️ Attention Required
⭐ New Features
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.