Spring
Follow
Spring LDAP 2026.06 Releases - Contains CVE Fix
Spring LDAP has released new versions 3.3.8, 4.0.4, and 4.1.0, which fix a critical authentication bypass vulnerability. The 4.1.0 release introduces new features detailed on the Spring LDAP website, and all changes are listed in the provided changelogs. Notably, open-source support has ended for older Spring LDAP generations, but commercial customers can update to specific versions that include the security fixes. These commercial versions are also integrated into recent Spring Boot releases and are accessible via a Spring Enterprise Subscription.