Forge Fate
Backend & Infrastructure

Spring Boot 4.1 Highlights: gRPC, Jackson, and HTTP Address Filtering

1 min read

Evidence and scope — Official-source overview

This overview summarizes changes from official announcements and release documentation. It does not present an application upgrade or execution results for individual features.

Spring Boot 4.1.0 was released on June 10, 2026.[S2] Here are three key features and a Maven build configuration change confirmed by the official release documentation.

gRPC Server, Client, and Test Support

Spring Boot 4.1 supports building and testing gRPC servers and clients.[S1] If your project uses gRPC, review the release notes to understand the scope of support and assess whether to adopt it.

Expanded Jackson Read and Write Settings

You can auto-configure Jackson’s common read features with spring.jackson.read.* and common write features with spring.jackson.write.*.[S1] Review these alongside your existing Jackson configuration when upgrading.

HTTP Request Address Filtering to Mitigate SSRF

Configuring an InetAddressFilter for reactive and blocking HTTP clients lets you block requests to specific addresses.[S1] The official announcement describes this as an SSRF mitigation feature.[S2] This should not be taken to mean it is enabled by default or provides complete protection against all SSRF attacks.[S1]

Check Maven Test AOT Settings Before Upgrading

To skip test AOT processing in Maven, you must use the maven.test.skip property instead of -DskipTests.[S1] If your build currently uses -DskipTests, check whether you also intend to skip test AOT processing.

Before upgrading, review the feature descriptions and upgrade guidance in the official release notes.[S1]

Sources

Report an error or share feedback

Open a draft with this article’s title and URL. Review the message and recipient before sending.

To: [email protected]

Open email draft

If no email app opens, copy these details into your usual email service.

Contact information