RepoJournal
Spring

@spring-projects

Spring Framework, Spring Boot, and the JVM enterprise layer

Keep up with Spring in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Java Full archive →

The Wire · Showcase

ESBUILD PATCHES CRITICAL HTTP REQUEST FLAW IN SPRING SECURITY

By RepoJournal · Filed · About Spring

Spring Security shipped an emergency esbuild bump overnight that closes a local development server vulnerability allowing backslash injection in HTTP requests.

The esbuild update from 0.25.0 to 0.28.1 [1] addresses GHSA-g7r4-m6w7-qqqr, a security issue where the development server was accepting malformed HTTP requests containing backslash characters that should have been rejected. This matters if you're running Spring Security's JavaScript toolchain in local development. Ship this upgrade before your next build. In parallel, Spring Integration quietly bumped protobuf-bom to 4.35.1 [2], a patch release with no breaking changes. On the reliability front, Spring Integration merged a retry harness for TcpOutboundGatewayTests that was cherry-picked to the 7.0.x branch [3], stabilizing flaky timeout tests. Spring Boot fixed a subtle auto-config bug [4] where SpringReactiveOpaqueTokenIntrospector was loading without WebFlux on the classpath, causing ClassNotFoundException on BodyInserters.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] Bump esbuild from 0.25.0 to 0.28.1 in /javascript ↗ spring-projects/spring-security
  2. [2] Bump com.google.protobuf:protobuf-bom from 4.35.0 to 4.35.1 ↗ spring-projects/spring-integration
  3. [3] RetryingTest for TcpOutboundGatewayTests.testGoodNetGWTimeout spring-projects/spring-integration
  4. [4] Stop auto-config of SpringReactiveOpaqueTokenIntrospector w/o WebFlux spring-projects/spring-boot

Quick answers

What shipped in Spring on June 14, 2026?
Spring Security shipped an emergency esbuild bump overnight that closes a local development server vulnerability allowing backslash injection in HTTP requests. In total, 2 commits and 2 pull requests landed.
Who contributed to Spring on June 14, 2026?
1 developer shipped this update, including dependabot[bot].
What were the notable Spring updates?
Bump esbuild from 0.25.0 to 0.28.1 in /javascript, Bump com.google.protobuf:protobuf-bom from 4.35.0 to 4.35.1, and RetryingTest for TcpOutboundGatewayTests.testGoodNetGWTimeout.

More from @spring-projects

Daily updates, in your inbox

Follow Spring

Keep up with Spring in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?

We use privacy-friendly analytics (Google Analytics, IP-anonymized) to see which pages help readers. No ads, and we never sell your data. See our Privacy Policy.