← Back to all articles

Spring Framework 7.0.9 Released: SpEL Compilation Off by Default, Forwarded Headers Need an Explicit Choice

JavaSecurityJVM

The last of the 7.0.x line

Spring Framework 7.0.9 was released on August 20, 2026. As a maintenance release on the 7.0.x line it adds no new features; the focus is on three things: tightening security boundaries, fixing memory leaks, and improving stability under high concurrency. The team has also made clear that 7.0.x ends here, with new features going to 7.1.x.

In other words, this is a release about stability, but two of its changes touch application code directly, so they are worth reading before you upgrade.

SpEL compilation is now off by default

This is the change that matters most. You used to be able to make SimpleEvaluationContext run compiled expressions via spring.expression.compiler.mode; starting with 7.0.9 that is disabled by default.

The reason is a run of vulnerabilities related to SpEL expression compilation (CVE-2026-41849, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852 and others). Plenty of enterprise applications never used expression compilation at all, yet were exposed because it was on by default, so the team reversed the default.

The consequence: if your application genuinely relies on the performance of compiled expressions and you can vouch for the source and content of every expression, you now have to opt in explicitly by calling .withCompilationSupported(). After upgrading, check whether such configuration exists before assuming the old behaviour still holds.

Forwarded headers need an explicit choice

ForwardedHeaderFilter (MVC) and ForwardedHeaderTransformer (WebFlux) now require you to state whether you use the standard Forwarded header or the legacy X-Forwarded-* family. In practice that means moving to the new constructors that take a boolean parameter.

The difference matters: Forwarded is a standardised header formally defined by the IETF in RFC 7239, carrying forwarding information in a single header, while X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Proto are de facto conventions whose formatting and implementations vary enough to cause inconsistency. The team has stated that the old no-argument constructors will be deprecated in 7.1.

Applications sitting behind Nginx or any kind of gateway should check this first. If forwarded-header parsing goes wrong, what breaks is the client's real IP and the protocol detection, which in turn affects access logs, rate limiting and redirect URLs, and typically only shows up in production.

Memory and stability fixes

Several changes target long-running stability. Annotation metadata no longer holds on to class file references, which reduces Metaspace pressure. Exponentiation on BigDecimal and BigInteger in SpEL now has an upper bound, closing off expressions crafted to exhaust CPU. URI parsing now ignores empty port values instead of failing on a formatting detail.

Two of the bug fixes stand out: the EclipseLink case where a singleton lock made every JDBC connection queue up under high load, and a Buffer leak in RSocket SETUP frame handling. There is also a forward-looking fix for native query creation failing with Hibernate 8.0 / JPA 4.0.

Upgrade advice

7.0.9 carries important security fixes, so applications on the 7.0.x line should pick it up. Before upgrading, focus on two kinds of code: anything touching SpEL compilation, and your forwarded-header parsing configuration. Spring Security, Spring GraphQL and related projects have already been aligned, so the upgrade path is fairly smooth.

If you are already evaluating 7.1, keep an eye on v7.1.0-M1 and v7.1.0-M2, as the GA is expected soon. For teams that still rely on SpEL compilation but cannot verify expression safety right away, the safer order is to take 7.0.9 for the security patches now and evaluate the compilation performance work as a separate iteration.