Skip to content

[fix][sec][branch-4.2] Upgrade Spring to 7.0.8 - #26270

Merged
lhotari merged 1 commit into
apache:branch-4.2from
lhotari:lh-fix-spring-cves-branch-4.2
Aug 4, 2026
Merged

lhotari merged 1 commit into
apache:branch-4.2from
lhotari:lh-fix-spring-cves-branch-4.2

Conversation

@lhotari

@lhotari lhotari commented Aug 4, 2026

Copy link
Copy Markdown
Member

Motivation

Spring Framework 6.2.12, currently used on branch-4.2, is affected by four CVEs disclosed on 2026-06-09:

CVE Severity (CVSS) Issue Affected artifact
CVE-2026-41848 Low (3.7) Denial of service via ReDoS in AntPathMatcher (CWE-1333) spring-core
CVE-2026-41850 High (7.5) Algorithmic denial of service via SpEL expressions (CWE-407) spring-expression
CVE-2026-41851 Medium (5.3) Denial of service via an unbounded SpEL expression cache (CWE-770) spring-expression
CVE-2026-41852 Low (3.7) Arbitrary zero-argument method invocation in SpEL (CWE-863) spring-expression

Why 7.0.8 and not 6.2.19? Both release lines contain the fixes, but Spring Framework 6.2 reached
end-of-life on 2026-06-30, making 6.2.19 the final release on that line. Staying on 6.2.x would leave
branch-4.2 without a supported upgrade path for any future Spring CVE. Spring Framework 7.0 is
supported until 2027-07-31.

Exposure in Pulsar. Pulsar does not evaluate SpEL expressions or use AntPathMatcher, so there is
no known exploitable path — this upgrade is dependency hygiene that also clears the CVEs from security
scanners. Spring is a test-scoped dependency of pulsar-broker and pulsar-client-tools, so it is
not part of the server or shell distributions; it ships only inside the pulsar-io-canal and
pulsar-io-batch-data-generator connector NARs.

This change is specific to branch-4.2. On master the Spring dependency has been removed entirely
(replaced by cron-utils in #26269), so there is no corresponding upstream commit to cherry-pick.

Modifications

Bump the spring.version property in the root pom.xml from 6.2.12 to 7.0.8.

This is the complete change; no source modifications were required. Spring Framework 7.0 requires
JDK 17+, which branch-4.2 already targets (maven.compiler.source/target are both 17).

The upgrade affects three modules, which are the only ones declaring Spring dependencies:

  • pulsar-io/batch-discovery-triggerers — the only Pulsar source file using a Spring API is
    CronTriggerer, which uses ThreadPoolTaskScheduler and CronTrigger. Both are unchanged in 7.0.
  • pulsar-io/batch-data-generator — declares spring-context; no direct Spring API usage.
  • pulsar-io/canal — declares Spring for the bundled canal.client/canal.common libraries, which
    themselves reference only 5 Spring methods (BeanUtils.copyProperties, and ReflectionUtils
    findField/getField/makeAccessible/setField). All 5 are present in 7.0.8 with identical
    signatures, so the major-version bump is binary compatible for this connector.

No LICENSE/NOTICE updates are needed: no distribution LICENSE.bin.txt lists Spring jars. (The
existing NOTICE.bin.txt mention of Spring is an attribution for Apache Commons Lang borrowing
StringUtils.containsWhitespace(), and is unrelated to the Spring version.)

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a dependency version upgrade without new test coverage. It was verified as follows:

  • All three affected modules compile cleanly from scratch against Spring 7.0.8 with release 17
    (mvn test-compile with the build cache disabled).
  • mvn dependency:tree resolves spring-core, spring-aop, spring-beans, spring-context,
    spring-expression, spring-jdbc, spring-tx and spring-orm uniformly at 7.0.8 with no
    version conflicts.
  • Binary compatibility of the bundled canal libraries was checked by extracting the Spring method
    references from their class files and confirming each signature still exists in the 7.0.8 jars.
  • checkstyle:check and license:check pass for all three modules.

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

Spring Framework is upgraded from 6.2.12 to 7.0.8. Spring is not on the broker runtime classpath; the
upgraded jars are bundled only in the pulsar-io-canal and pulsar-io-batch-data-generator connector
NARs.

@lhotari
lhotari merged commit d8df12d into apache:branch-4.2 Aug 4, 2026
52 of 53 checks passed
lhotari added a commit that referenced this pull request Aug 4, 2026
nodece pushed a commit to ascentstream/pulsar that referenced this pull request Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants