Spring Boot version lifecycle

framework · Broadcom (Spring)

Current status

supported

Supported version lines, end-of-life status, and latest releases for Spring Boot — derived from official vendor sources, not third-party EOL aggregators.

Spring Boot helps build production-grade Spring applications with embedded servers, starters, and opinionated auto-configuration.

Security: 12 tracked advisories. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

23

Supported

22

EOL lines

0

Latest stable

4.1.1

2026-08-20

Releases tracked

282

At a glance

Latest release

4.1.1

Line 4.1

Recommended support line

4.1

standard support

Status

STANDARD SUPPORT

Newest supported: 4.1

EOL

Not published

Exact date not officially published

Recommended line: 4.1 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

22 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
4.1
standard supportlow
4.1.12026-08-20Not officially publishedlow
4.0
standard supportlow
4.0.82026-08-21Not officially publishedlow
3.5
standard supportlow
3.5.162026-06-25Not officially publishedlow
3.4
standard supportlow
3.4.132025-12-18Not officially publishedlow
3.3
standard supportlow
3.3.132025-06-19Not officially publishedlow
3.2
standard supportlow
3.2.122024-11-21Not officially publishedlow
3.1
standard supportlow
3.1.122024-05-23Not officially publishedlow
3.0
standard supportlow
3.0.132023-11-23Not officially publishedlow
2.7
standard supportlow
2.7.182023-11-23Not officially publishedlow
2.6
standard supportlow
2.6.152023-05-18Not officially publishedlow
2.5
standard supportlow
2.5.152023-05-18Not officially publishedlow
2.4
standard supportlow
2.4.132021-11-18Not officially publishedlow
2.3
standard supportlow
2.3.122021-06-10Not officially publishedlow
2.2
standard supportlow
2.2.132021-01-14Not officially publishedlow
2.1
standard supportlow
2.1.182020-10-29Not officially publishedlow
2.0
standard supportlow
2.0.92019-04-03Not officially publishedlow
1.5
standard supportlow
1.5.222019-08-06Not officially publishedlow
1.4
standard supportlow
1.4.72023-09-11Not officially publishedlow
1.3
standard supportlow
1.3.82023-09-11Not officially publishedlow
1.2
standard supportlow
1.2.82023-09-11Not officially publishedlow
1.1
standard supportlow
1.1.122023-09-11Not officially publishedlow
1.0
standard supportlow
1.0.22023-09-11Not officially publishedlow

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 4.1standard support
    standard support
  • 4.0standard support
    standard support
  • 3.5standard support
    standard support
  • 3.4standard support
    standard support
  • 3.3standard support
    standard support
  • 3.2standard support
    standard support
  • 3.1standard support
    standard support
  • 3.0standard support
    standard support
  • 2.7standard support
    standard support
  • 2.6standard support
    standard support
  • 2.5standard support
    standard support
  • 2.4standard support
    standard support
  • 2.3standard support
    standard support
  • 2.2standard support
    standard support
  • 2.1standard support
    standard support
  • 2.0standard support
    standard support

Showing 16 of 22 lines with lifecycle periods. See the directory below for the full list.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2026-40977
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40976
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40975
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40974
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40973
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40972
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40971
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-40970
    Affected:
    >=4.0.0,<4.0.6
    Fixed in:
    4.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-22733

    Authentication Bypass under Actuator CloudFoundry endpoints

    Affected:
    >=4.0.0,<4.0.4
    Fixed in:
    4.0.4
    Source:
    OSV source · Advisory
  • CVE-2026-22731

    Authentication Bypass under Actuator Health groups paths

    Affected:
    >=4.0.0,<4.0.4
    Fixed in:
    4.0.4
    Source:
    OSV source · Advisory
  • CVE-2023-34055

    Spring Boot server Web Observations DoS Vulnerability

    Affected:
    >=3.1.0,<=3.1.5
    Source:
    OSV source · Advisory
  • CVE-2023-20883
    Affected:
    >=3.0.0,<2.5.14
    Fixed in:
    2.5.14
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

4.14.03.53.4
Statusstandard supportstandard supportstandard supportstandard support
Latest4.1.14.0.83.5.163.4.13
Released2026-08-202026-08-212026-06-252025-12-18
EOLNot officially publishedNot officially publishedNot officially publishedNot officially published
Risklowlowlowlow

Recent releases

Latest release date 2026-08-20 · 2 in last 30 days · 6 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Spring Boot 4.1 (standard support).

Compatibility

Evidence-backed Spring Boot compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Data coverage

Version lines
23
Concrete releases
282
Supported lines
22
EOL lines
0
Lifecycle coverage
22/23
EOL coverage
0/23
Provenance coverage
22/23

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-01
Latest source update
2026-09-01

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
4.1
standard supportlow
4.1.12026-08-20Not officially published
4.0
standard supportlow
4.0.82026-08-21Not officially published
3.5
standard supportlow
3.5.162026-06-25Not officially published
3.4
standard supportlow
3.4.132025-12-18Not officially published
3.3
standard supportlow
3.3.132025-06-19Not officially published
3.2
standard supportlow
3.2.122024-11-21Not officially published
3.1
standard supportlow
3.1.122024-05-23Not officially published
3.0
standard supportlow
3.0.132023-11-23Not officially published
2.7
standard supportlow
2.7.182023-11-23Not officially published
2.6
standard supportlow
2.6.152023-05-18Not officially published
2.5
standard supportlow
2.5.152023-05-18Not officially published
2.4
standard supportlow
2.4.132021-11-18Not officially published
2.3
standard supportlow
2.3.122021-06-10Not officially published
2.2
standard supportlow
2.2.132021-01-14Not officially published
2.1
standard supportlow
2.1.182020-10-29Not officially published
2.0
standard supportlow
2.0.92019-04-03Not officially published
1.5
standard supportlow
1.5.222019-08-06Not officially published
1.4
standard supportlow
1.4.72023-09-11Not officially published
1.3
standard supportlow
1.3.82023-09-11Not officially published
1.2
standard supportlow
1.2.82023-09-11Not officially published
1.1
standard supportlow
1.1.122023-09-11Not officially published
1.0
standard supportlow
1.0.22023-09-11Not officially published

Archive / no vendor EOL schedule

Lines without a published support schedule from the vendor.

Version lineStatusLatest releaseReleasedEOL
4.2
unknownmedium
Not officially published