Spring Boot 1.x — End of Life

EOL
EOL: Aug 6, 20191 release in this series0 CVEs

Spring Boot 1.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
1.5Jan 30, 2017Aug 6, 20191.5.22EOL

CVEs affecting Spring Boot 1.x (0)

No CVEs tracked for Spring Boot 1.x.

Spring Boot 1.x is EOL — migrate to Spring Boot 2.x

Spring Boot 2.x is the next major release. Plan your upgrade before Spring Boot 1.x stops receiving security patches.

See Spring Boot 2.x

Frequently asked questions

Is Spring Boot 1 end of life?

Yes. All Spring Boot 1.x releases have reached end of life and no longer receive security patches. Migrate to Spring Boot 2.x as soon as possible.

What CVEs affect Spring Boot 1?

No CVEs are currently tracked for Spring Boot 1.x in our database. This may mean no vulnerabilities have been recorded yet, or the data is still syncing.

What is the latest Spring Boot 1 version?

The latest Spring Boot 1.x patch release is 1.5.22, released on August 6, 2019. Always run the latest patch to benefit from all security fixes.

How to migrate from Spring Boot 1 to Spring Boot 2?

To migrate from Spring Boot 1 to Spring Boot 2: (1) review the official Spring Boot 2 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Spring Boot 1 in production?

No. Spring Boot 1 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA