Will Spring Cloud AWS 3.4.x receive security updates for Spring Boot 3.5? #1682
Replies: 1 comment
|
I would treat this as a compatibility and support-policy question rather than assume that a 3.4.x backport will happen. If an application must remain on Spring Boot 3.5, first confirm whether the CVE is reachable in the enabled Spring Cloud AWS modules and configuration. Then ask the maintainers whether a patched 3.4.x release is planned; only they can provide a supported backport commitment. If no patched 3.x release is available, the supported options are to upgrade to the Spring Boot and Spring Cloud AWS 4.x compatibility line, or temporarily isolate the affected integration and apply the vendor mitigation while planning that upgrade. I would not force Cloud AWS 4.x onto Boot 3.5. For dependency hygiene, pin the Cloud AWS line explicitly and monitor the project security advisories. A temporary Maven or Gradle exclusion can remove a transitive CVE only after verifying that the affected class or feature is not used; exclusions are not a general fix. |
Uh oh!
There was an error while loading. Please reload this page.
Hello maintainers,
According to the compatibility matrix, Spring Cloud AWS 3.4.x is the last release line compatible with Spring Boot 3.5.x and Spring Cloud 2025.0.x. Spring Cloud AWS 4.x requires Spring Boot 4.0.x.
We currently need to remain on Spring Boot 3.5, but Spring Cloud AWS 3.4.2 is affected by CVE-2026-44308. The advisory states that versions 3.0.0 through 3.4.2 are affected, the fix is available only in 4.0.2, and the 3.x line will not receive the fix.
This appears to leave Spring Boot 3.5 users without a compatible patched release. Maven Repository also reports CVE-2025-14763 through dependencies, although its applicability depends on whether the affected S3 Encryption Client and vulnerable feature are actually used.
Could you please clarify:
Thank you.
All reactions