NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #162 by repository stars
Spring WebFlux
Last release 14 days ago
24 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Rarely documented
notes for 9 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
198 releases · first in 2017
Deprecate SpelParserConfiguration constructors in favor of the builder API #37190
SpelParserConfiguration constructors in favor of the builder API #37190SimpleMessageConverter.fromMessage() can return null despite @NullMarked package #37148MockCookie#parse(String) validation #37136PropertyEditorRegistrySupport's addStrippedPropertyPaths() #37020DataBinder #37019SimpleJdbcInsert #37014PropertyAccessorUtils #36999Property #37139MergedAnnotations #37135Property constructor in SpEL's ReflectivePropertyAccessor #37123BeanFactory.getBean(String, ParameterizedTypeReference) to respect AOP proxy #37047OptionalToObjectConverter applicability check #36913Property name resolution for record-style accessors #36911Thank you to all the contributors who worked on this release:
@DevJunz, @Eymenonar, @Sineaggi, @Will-thom, @blackdurumi, @cookie-meringue, @desiderantes, @dxbjavid, @froggy0m0, @gregjotau, @heka1024, @junhyeong9812, @junhyung8795, @kilink, @lArtiquel, @marschall, @mateo-maza, @ngocnhan-tran1996, @noojung, @quaff, @sabberworm, @seonwooj0810, @shaggyinsomniac, @verhasi, and @vpavic
One column per quarter.
The default constructor with the existing behaviour of checking both types of headers is still available but deprecated and marked for removal. The ne…
ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each require a boolean argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property enables use of "X-Forwarded-Prefix" if needed. The default constructor with the existing behaviour of checking both types of headers is still available but deprecated and marked for removal. The new constructor makes forwarded header processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section, as well as related changes in Spring Boot spring-projects/spring-boot#51030. #37072@ContextConfiguration #31456AbstractFactoryBean #37091FullyQualifiedConfigurationBeanNameGenerator #37038ExponentialBackOff #36943ClassNotFoundException for missing class resource in ThrowawayClassLoader #36938isAssignableFrom() with isInstance() where feasible #36899DataSize converters to DefaultConversionService #36830ObservationThreadLocalAccessor when a test has an active ApplicationContext #36817ApplicationContext #36782String#replace instead of String#replaceAll where appropriate #36678Date copies for SimpleMailMessage sentDate #36626StandardMethodMetadata with ASM/ClassFile support for getReturnTypeName() #36619BeanRegistrarDsl #36601TypeNotPresentException during annotation processing #36593methodIdentification() method in CacheAspectSupport #36560ResolvableType.forParameter() factory method #36545Assert.notNull() checks in ResolvableType #36544ParameterResolutionDelegate #36534HttpMethod.valueOf() #36518classpath*: support for ResourceLoader#getResource with fully specified resource path #36415Optional with null-safe and Elvis operators #36330@PersistenceAgent injection #36264doPatch() method in FrameworkServlet #36247@BootstrapWith annotation to override a meta-annotation within the same composed annotation #35938BeanRegistrar #21497@MockitoBean and @MockitoSpyBean on test constructor parameters #36096AnnotationDescriptor.findAllLocalMergedAnnotations fails to find interface annotations #36975InputStream in ThrowawayClassLoader #36933@RequestBody deserialization) #36890DefaultMvcResult when catching InterruptedException #36876Thank you to all the contributors who worked on this release:
@PaulNgo-BlueOC, @arnabnandy7, @bebeis, @codingkiddo, @cookie-meringue, @daguimu, @dominik-kovacs, @jhan0121, @junhyeong9812, @leestana01, @mkurz, @ngocnhan-tran1996, @quaff, @s-chan-o, @samueldlightfoot, @seregamorph, @shenjianeng, and @yeomin4242
Host header initialization breaking change in StompRelayMessageBrokerHandler #36907
ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #37035@Nullable annotations when treating Map.remove() as returning @Nullable #37067AbstractNestablePropertyAccessor #37036SimpleEvaluationContext #37035BigDecimal/BigInteger power operations in SpEL #37034getSession(*) in MockHttpServletRequest #36926domainToAscii with current WhatWG spec #37018ButtonTag value attribute processing #37017InlineList is cached as a mutable list in compiled mode #37001Indexer reuses invalid cached PropertyAccessor #36986ConstructorExecutor #36985MimeTypeUtils raises StringIndexOutOfBoundsException for some invalid mime types #36971ExponentialBackOff jitter #36932@ActiveProfiles ordering #36950Thank you to all the contributors who worked on this release:
@ZaMan0806, @alexisgra, @alshain, @gianmarcoschifone, @junhyeong9812, @msridhar, @perovic, @quaff, and @samueldlightfoot
CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module"
This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs:
ClassLoader from DefaultDeserializer #36833AntPathMatcher #36799SpringVersion.getVersion() to "major.minor.patch" format #36785ExchangeFilterFunctions#basicAuthentication #36777NullValue instances in AbstractValueAdaptingCache #36727Flow #36667CookieLocaleResolver#setLocaleContext #36869ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36835PropertyAccessorUtils #36765@Conditional gating of nested @Configuration classes #36831validateExistingTransaction #36767Thank you to all the contributors who worked on this release:
@0AndWild, @Dennis-Mircea, @cookie-meringue, @daguimu, @dmitrysulman, @kilink, @kzander91, @leestana01, @mguiking, @quaff, @seonwooj0810, @sgerke-1L, @shenjianeng, @tianhaocui, @wushiyuanmaimob, and @zmovo
Deprecate methodIdentification() in CacheAspectSupport for removal #36575
SpringValidatorAdapter and MethodValidationAdapter performance #36621Flux in KotlinSerializationJsonDecoder #36597methodIdentification() in CacheAspectSupport for removal #36575ApplicationListenerMethodAdapter#getTargetMethod() public #36558SpringExtension via Spring or JUnit properties #36460MergedAnnotation does not use ClassLoader for method or field #36606@Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36611AnnotatedTypeMetadata no longer retains source declaration order on Java 24+ #36598MergedAnnotation.asMap() fails when an attribute references a non-existent class #36586FileSystemResource does not strictly follow the Resource#isReadable() contract #36584AbstractJsonHttpMessageConverter.writeInternal(Object, Type, Writer) #36565SseServerResponse #36537AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36524DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36506CoroutineUtils #36449spring.profiles.active is ignored by @ActiveProfiles #36600MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36567TypeDescriptor.array() Javadoc #36549@MockitoBean, etc.) #36541Thank you to all the contributors who worked on this release:
@Mohak-Nagaraju, @Sineaggi, @T45K, @angry-2k, @bebeis, @cookie-meringue, @dmitrysulman, @elgunshukurov, @itsmevichu, @junhyung8795, @msridhar, @nameearly, @tobifasc, and @xxxxxxjun
Log warning when default context configuration is ignored within test class hierarchies #36390
ResourceHandlerUtils in ScriptTemplateView #36458ScriptTemplateViewTests #36456ConfigurationClassBeanDefinitionReader #36453AbstractTestContextBootstrapper #36430resolveContextLoader() only once in AbstractTestContextBootstrapper #36425toString() with modern JDKs #36417setDefaultCharset() in AbstractResourceBasedMessageSource #36413Predicate<RequestPath>> in path API version resolver #36398ResponseEntity<Mono<T>> (or Kotlin suspend function) controller method #36357FullyQualifiedConfigurationBeanNameGenerator in Javadoc and reference docs #36455@Fallback alongside Primary in the reference manual and @Bean Javadoc #36439UriComponentsBuilder and polish examples #36403@Configuration classes over XML and Groovy in testing chapter #36393BeanPostProcessor and BeanFactoryPostProcessor #34964Thank you to all the contributors who worked on this release:
@AgilAghamirzayev, @aavoronin93, @cetf9h, @froggy0m0, @gbouwen, @husseinvr97, @jisub-dev, @ngocnhan-tran1996, @siom79, and @xxxxxxjun
Optimize request and response header handling in Spring MVC #36334
AnnotatedMethod annotation cache in derived instances #36322MediaType(MediaType, Charset) constructor #36318@Autowired as a meta-annotation #36315required attribute lookup for @Autowired annotations #36314@ResponseBody presence per controller class in RequestResponseBodyMethodProcessor #36311Optional with null-safe and Elvis operators are not compilable #36331ListenableFuture in documentation #36313Thank you to all the contributors who worked on this release:
@Niravil and @TAKETODAY
Cache method annotations in MethodParameter and AnnotatedMethod #36307
MethodParameter and AnnotatedMethod #36307@Lazy as a meta-annotation at arbitrary depths #36306@Validated as a meta-annotation at arbitrary depths #36305setPackagesToScan configuration method to LocalEntityManagerFactoryBean #36270beforeRetry callback with RetryState argument #36245ProxyFactory in HttpServiceProxyFactory used to create HTTP service proxies #36225DataBufferUtils.write() with NettyDataBuffer on JDK 25 hangs indefinitely #36184RestClient.ResponseSpec#requiredBody #36173DefaultMessageListenerContainer is not applied consistently in case of listener setup failure #36143LocalEntityManagerFactoryBean#setDataSource work on Hibernate as well as EclipseLink #36271StompBrokerRelayMessageHandler fails to restart due to test context pausing #36266System.exit on startup (against multiple shutdown hooks) #36260BeanRegistrar implementing ImportAware #36242@Retryable on annotated interfaces #36233Netty4HeadersAdapter.remove returns empty list instead of null for non-existing key #36226@Nullable #36191EclipseLinkConnectionHandle can fail against transaction isolation race condition #36165Redirecting to a resource section #36284@SpringExtensionConfig in the reference manual #36240LocalContainerEntityManagerFactoryBean#setPersistenceUnitName javadoc #36205@GetMapping("/base") is combined with method level @GetMapping("/") #36198DispatcherServlet snippets #36175getErrors() with getBindingResult() in examples #36170Thank you to all the contributors who worked on this release:
@Ivarz, @catturtle123, @chschu, @deejay1, @dingqianwen, @dungdm93, @furaizi, @izeye, @kchung1995, @kilink, @msridhar, @ngocnhan-tran1996, @pgoslatara, @philwebb, @pisek, and @shub-est
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module"
This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs:
AntPathMatcher #36886ClassLoader from DefaultDeserializer #36839NullValue instances in AbstractValueAdaptingCache #36728CookieLocaleResolver#setLocaleContext #36870ConfigurationClassParser incorrectly removes component-scanned bean when the same class is also registered under a different name via XML #36849Add missing @Deprecated (forRemoval = true) for deleted in 7.0 #36591
SpringValidatorAdapter and MethodValidationAdapter performance #36624@Deprecated(forRemoval = true) for deleted in 7.0 #36591methodIdentification() in CacheAspectSupport for removal #36576CoroutineUtils #36643@Sql fails if DataSource is wrapped in a TransactionAwareDataSourceProxy #36630MergedAnnotation does not use ClassLoader for method or field #36614AnnotationBeanNameGenerator fails when an annotation references a non-existent class #36588FileSystemResource does not strictly follow the Resource#isReadable() contract #36585DefaultJmsListenerContainer may hang in an endless loop in doShutdown #36511spring.profiles.active is ignored by @ActiveProfiles #36636MergedAnnotation.asAnnotationAttributes() Javadoc incorrectly states that it creates an immutable map #36568@MockitoBean, etc.) #36542Leverage ResourceHandlerUtils in ScriptTemplateView #36459
ResourceHandlerUtils in ScriptTemplateView #36459ScriptTemplateViewTests #36457ConfigurationClassBeanDefinitionReader #36454AbstractTestContextBootstrapper #36431@javax.validation.Constraint from convention-based annotation attribute override check #36412MediaType(MediaType, Charset) constructor #36351@Fallback alongside Primary in the reference manual and @Bean Javadoc #36441BeanPostProcessor and BeanFactoryPostProcessor #36436UriComponentsBuilder and polish examples #36406@Configuration classes over XML and Groovy in testing chapter #36394Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →