Repository navigation
[fix][sec][branch-4.2] Upgrade Spring to 7.0.8 - #26270
Merged
Merged
Conversation
nodece
approved these changes
Aug 4, 2026
lhotari
added a commit
that referenced
this pull request
Aug 4, 2026
(cherry picked from commit d8df12d)
nodece
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Aug 28, 2026
(cherry picked from commit d8df12d)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Spring Framework 6.2.12, currently used on
branch-4.2, is affected by four CVEs disclosed on 2026-06-09:AntPathMatcher(CWE-1333)spring-corespring-expressionspring-expressionspring-expressionWhy 7.0.8 and not 6.2.19? Both release lines contain the fixes, but Spring Framework 6.2 reached
end-of-life on 2026-06-30, making 6.2.19 the final release on that line. Staying on 6.2.x would leave
branch-4.2without a supported upgrade path for any future Spring CVE. Spring Framework 7.0 issupported until 2027-07-31.
Exposure in Pulsar. Pulsar does not evaluate SpEL expressions or use
AntPathMatcher, so there isno known exploitable path — this upgrade is dependency hygiene that also clears the CVEs from security
scanners. Spring is a
test-scoped dependency ofpulsar-brokerandpulsar-client-tools, so it isnot part of the server or shell distributions; it ships only inside the
pulsar-io-canalandpulsar-io-batch-data-generatorconnector NARs.This change is specific to
branch-4.2. Onmasterthe Spring dependency has been removed entirely(replaced by
cron-utilsin #26269), so there is no corresponding upstream commit to cherry-pick.Modifications
Bump the
spring.versionproperty in the rootpom.xmlfrom6.2.12to7.0.8.This is the complete change; no source modifications were required. Spring Framework 7.0 requires
JDK 17+, which
branch-4.2already targets (maven.compiler.source/targetare both17).The upgrade affects three modules, which are the only ones declaring Spring dependencies:
pulsar-io/batch-discovery-triggerers— the only Pulsar source file using a Spring API isCronTriggerer, which usesThreadPoolTaskSchedulerandCronTrigger. Both are unchanged in 7.0.pulsar-io/batch-data-generator— declaresspring-context; no direct Spring API usage.pulsar-io/canal— declares Spring for the bundledcanal.client/canal.commonlibraries, whichthemselves reference only 5 Spring methods (
BeanUtils.copyProperties, andReflectionUtilsfindField/getField/makeAccessible/setField). All 5 are present in 7.0.8 with identicalsignatures, so the major-version bump is binary compatible for this connector.
No
LICENSE/NOTICEupdates are needed: no distributionLICENSE.bin.txtlists Spring jars. (Theexisting
NOTICE.bin.txtmention of Spring is an attribution for Apache Commons Lang borrowingStringUtils.containsWhitespace(), and is unrelated to the Spring version.)Verifying this change
This change is a dependency version upgrade without new test coverage. It was verified as follows:
release 17(
mvn test-compilewith the build cache disabled).mvn dependency:treeresolvesspring-core,spring-aop,spring-beans,spring-context,spring-expression,spring-jdbc,spring-txandspring-ormuniformly at7.0.8with noversion conflicts.
references from their class files and confirming each signature still exists in the 7.0.8 jars.
checkstyle:checkandlicense:checkpass for all three modules.Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes
Spring Framework is upgraded from 6.2.12 to 7.0.8. Spring is not on the broker runtime classpath; the
upgraded jars are bundled only in the
pulsar-io-canalandpulsar-io-batch-data-generatorconnectorNARs.