NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #805 by repository stars
Spring Security
Last release 13 days ago
25 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Rarely documented
notes for 7 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
18 years old
286 releases · first in 2008
@EnableMethodSecurity should pick up PermissionEvaluator bean
@EnableMethodSecurity should pick up PermissionEvaluator beanThank you to all the contributors who worked on this release:
@Siggen, @anthonydahanne, @avsan, @iain-henderson, @morokosi, @rwinch, and @sunghyun1999
One column per quarter.
Add Implicit CorsConfigurationSource/PreFlightRequestHandler Detection to <cors> XML Namespace #19542
<cors> XML Namespace #19542DefaultLoginPageGeneratingFilter Javadoc Link #19252AuthorizationDecision Cast #19283OAuth2PushedAuthorizationRequestUri parsing #19445FAILURE: Build failed with an exception.
Thank you to all the contributors who worked on this release:
Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
DefaultLoginPageGeneratingFilter Javadoc Link #19252AuthorizationDecision Cast #19283OAuth2PushedAuthorizationRequestUri parsing #19445@springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503Opaque token introspectors should not allow empty credentials #19201
@springio/antora-extensions from 1.14.11 to 1.14.12 in /docs #19235Add AllRequiredFactorsAuthorizationManager.anyOf #18960
AllRequiredFactorsAuthorizationManager.anyOf #18960PreFlightRequestFilter Support #18926@WithSecurityContext thread scope #18812@springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18946@springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19030@springio/antora-extensions from 1.14.9 to 1.14.11 in /docs #19053@springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18913Thank you to all the contributors who worked on this release:
@aspan, @dasog94, @evgeniycheban, @franticticktick, @gbaso, @jkuhel, @ribafish, @rwinch, @suuuuuuminnnnnn, @therepanic, @wonderfulrosemari, @yxinot, and @ziqin
Add postProcessor to SpringOpaqueTokenIntrospector Builders #18625
postProcessor to SpringOpaqueTokenIntrospector Builders #18625PasswordEncoder#encode implementations #18490ActiveDirectoryLdapAuthenticationProvider to use LdapClient #18627CsrfTokenRequestAttributeHandler#setCsrfRequestAttributeName as Nullable #18620@Nullable in Switch User and FactorGrantedAuthority #18765WWW-Authenticate for Basic Auth #18760OAuth2AuthenticatedPrincipal in Jwt-based authentication flow #17191RsaKeyConverters #18599@param response Javadoc (cannot be null) #18795targetDomainObject as @Nullable in PermissionEvaluator #18796@antora/collector-extension from 1.0.2 to 1.0.3 #18851@antora/collector-extension from 1.0.2 to 1.0.3 in /docs #18852Thank you to all the contributors who worked on this release:
@023-dev, @DDINGJOO, @Hann244, @chanani, @coehgns, @earlgrey02, @evgeniycheban, @itsmevichu, @jkuhel, @joshlong, @kimyounguk1, @kmw10693, @ngocnhan-tran1996, @nidhogg5, @pahlevani, @rwinch, @scordio, @therepanic, and @wonderfulrosemari
Nothing published for this version
Nothing published for this version
Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
DefaultLoginPageGeneratingFilter Javadoc Link #19252AuthorizationDecision Cast #19283OAuth2PushedAuthorizationRequestUri parsing #19445@springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19504Thank you to all the contributors who worked on this release:
@ArzMeow, @big-cir, @junhyeong9812, @jyx-07, @ngocnhan-tran1996, @skdas20, @snowykte0426, and @therepanic
FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19137
FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19137Add XML Based shouldWriteHeadersEagerly tests #19018
@springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #19054@springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18953@springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19029@springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18957Thank you to all the contributors who worked on this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19136
FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19136Add CredentialRecordOwnerAuthorizationManager #19004
FilterChainProxy#getFilters(String) javadoc #18258HttpMethodRequestMatcher #18914HttpSessionRequestCache#getMatchingRequest query string parsing #16914@springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #19055@springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18956@springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19031@springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18952Thank you to all the contributors who worked on this release:
@Kehrlann, @as1605, @johnycho, @ngocnhan-tran1996, @rwinch, and @sankranty
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →