Spring security advisory (AV26-386)

Serial number: AV26-386
Date: April 23, 2026

On April 23, 2026, Spring published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:

  • Spring Boot – 4.0.x versions prior to 4.0.6
  • Spring Boot – 3.5.x versions prior to 3.5.14
  • Spring Boot – 3.4.x versions prior to 3.4.16
  • Spring Boot – 3.3.x versions prior to 3.3.19
  • Spring Boot – 2.7.x versions prior to 2.7.33

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

Date modified: