RepoJournal
Spring

@spring-projects

Spring Framework, Spring Boot, and the JVM enterprise layer

Keep up with Spring in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Java Full archive →

The Wire · Showcase

Logback 1.6.3 shuts down CVE-2026-19880 in Spring Security and Session

By RepoJournal · Filed · About Spring

A critical logback security patch is forcing the entire Spring ecosystem to move in lockstep.

Dependabot is pulling logback 1.6.3 into both spring-security [1] and spring-session [2] to close CVE-2026-19880, which targets MDCBasedDiscriminator. The release notes state the fix is "In response CVE-2026-19880", and it's a drop-everything upgrade if you use SiftingAppender in production. Meanwhile, spring-security also bumps jackson-bom to 3.2.2 [3], keeping JSON handling current with FasterXML's latest patch release. Over in spring-ldap, antora advances to 3.2.0-rc.3 [4], adding an antoraVersion property to the playbook builder, which mainly matters for docs tooling. With only 4 PRs across 3 repos, this is a quiet day, but the logback CVE makes the upgrade imperative.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 ↗ spring-projects/spring-security
  2. [2] Bump ch.qos.logback:logback-core from 1.6.1 to 1.6.3 ↗ spring-projects/spring-session
  3. [3] Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2 ↗ spring-projects/spring-security
  4. [4] Bump antora from 3.2.0-rc.2 to 3.2.0-rc.3 ↗ spring-projects/spring-ldap

Quick answers

What shipped in Spring on August 18, 2026?
A critical logback security patch is forcing the entire Spring ecosystem to move in lockstep. In total, 4 pull requests landed.
Who contributed to Spring on August 18, 2026?
1 developer shipped this update, including dependabot.
What were the notable Spring updates?
Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3, Bump ch.qos.logback:logback-core from 1.6.1 to 1.6.3, and Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2.

More from @spring-projects

Daily updates, in your inbox

Follow Spring

Keep up with Spring in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?