Skip to content

Missing class StringUtils since 7.1.0, causing NoClassDefFoundError #19867

Description

@ewan-escience

Describe the bug
Since version 7.1.0, the method matches of the class Argon2PasswordEncoder uses the class org.springframework.util.StringUtils. However, this class is missing from the jar file downloaded my Maven, causing a java.lang.NoClassDefFoundError to be thrown.

To Reproduce
I've included an example below.

Expected behavior
The class org.springframework.util.StringUtils should be packaged so that no java.lang.NoClassDefFoundError is thrown

Sample

This example was created by Google AI and slightly edited by me (the of this report was not written by AI).

Create this pom.xml

<project xmlns="http://apache.org"
         xmlns:xsi="http://w3.org"
         xsi:schemaLocation="http://apache.org http://apache.org">
    <modelVersion>4.0.0</modelVersion>

    <groupId>com.example</groupId>
    <artifactId>argon2-demo</artifactId>
    <version>1.0-SNAPSHOT</version>

    <properties>
        <maven.compiler.source>17</maven.compiler.source>
        <maven.compiler.target>17</maven.compiler.target>
    </properties>

    <dependencies>
        <!-- The core Spring Security Crypto library -->
        <dependency>
            <groupId>org.springframework.security</groupId>
            <artifactId>spring-security-crypto</artifactId>
            <version>7.1.0</version>
        </dependency>

        <!-- Required runtime dependency for Argon2 support -->
        <dependency>
            <groupId>org.bouncycastle</groupId>
            <artifactId>bcprov-jdk18on</artifactId>
            <version>1.86</version>
        </dependency>
        
        <!-- Required because spring-security-crypto uses commons-logging internally -->
		<dependency>
			<groupId>org.springframework</groupId>
			<artifactId>spring-jcl</artifactId>
			<version>6.2.19</version>
		</dependency>
    </dependencies>
</project>

Create src/main/java/App.java:

import org.springframework.security.crypto.argon2.Argon2PasswordEncoder;

public class App {
    public static void main(String[] args) {
        // Initialize the default Argon2 encoder
        // Default parameters: salt length 16, hash length 32, parallelism 1, memory 16384, iterations 2
        Argon2PasswordEncoder encoder = Argon2PasswordEncoder.defaultsForSpringSecurity_v5_8();

        String rawPassword = "mySecurePassword123";

        // 1. Hash the password (this automatically handles salt generation)
        String hashedPassword = encoder.encode(rawPassword);
        System.out.println("Encoded Hashed Password: " + hashedPassword);

        // 2. Verify a matching password
        boolean isMatch = encoder.matches(rawPassword, hashedPassword);
        System.out.println("Password Match Status: " + isMatch); // true

        // 3. Verify a wrong password
        boolean isWrongMatch = encoder.matches("wrongPassword", hashedPassword);
        System.out.println("Wrong Password Match Status: " + isWrongMatch); // false
    }
}

Then run

mvn compile exec:java -Dexec.mainClass="App"

When using version 7.1.0 or 7.1.1, this will error as described above, while with version 7.0.7, this will succeed.

Activity

  1. changed the title [-]Missing class StringUtils since `7.1.0`, causing `NoClassDefFoundError`[/-] [+]Missing class `StringUtils` since `7.1.0`, causing `NoClassDefFoundError`[/+] on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions