Spring Boot 3.2 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
Spring Boot 3.2 reached end of life on 31 Dec 2024. It no longer receives security fixes.
Support timeline
Official dates, read directly from api.spring.io and repo1.maven.org.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 23 Nov 2023 | — |
| End of life | 31 Dec 2024 | 1.6 years ago |
| Extended support ends | 31 Dec 2025 | over |
| Latest release | 3.2.12 · 21 Nov 2024 | final |
The cost of staying: CVEs since end of life
10 Spring Boot vulnerabilities have been published since 31 Dec 2024. All were fixed in supported branches — 3.2 received none of them. Source: NVD.
Spring Boot CVEs published since 3.2's EOL, by year
1 of the 10 are rated critical · data refreshed 2026-08-09
Published 28 Apr 2026 · rated critical — fixed in supported branches only, never in 3.2. Details
Published 19 Mar 2026 · rated high — fixed in supported branches only, never in 3.2. Details
Published 20 Mar 2026 · rated high — fixed in supported branches only, never in 3.2. Details
This product uses data from the NVD API but is not endorsed or certified by the NVD.
Where to go from 3.2
Recommended target: Spring Boot 4.1 (supported until 31 Jul 2027).
The newest actively supported branch is Spring Boot 4.1 (latest release 4.1.0).
Frequently asked questions
Is Spring Boot 3.2 still safe to use?
No. Spring Boot 3.2 stopped receiving security fixes on 31 Dec 2024. Since then, 10 Spring Boot vulnerabilities have been published and fixed in supported branches — Spring Boot 3.2 received none of those fixes.
Can I still download Spring Boot 3.2?
Yes — the final release (3.2.12) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Spring Boot 3.2 to?
Upgrade to Spring Boot 4.1, the newest actively supported branch (supported until 31 Jul 2027).