惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Hugging Face - Blog
Hugging Face - Blog
F
Fortinet All Blogs
G
Google Developers Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Y
Y Combinator Blog
博客园_首页
Martin Fowler
Martin Fowler
博客园 - 司徒正美
MyScale Blog
MyScale Blog
宝玉的分享
宝玉的分享
B
Blog
有赞技术团队
有赞技术团队
A
About on SuperTechFans
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
Jina AI
Jina AI

Spring

A Bootiful Podcast: Joe Grandja on Spring Authorization Server, OAuth, and so much more Spring Modulith 2.2 M1, 2.1.1, 2.0.8, and 1.4.13 released This Week in Spring - August 25th, 2026 Spring AI 2.0.1 Available Now A Bootiful Podcast: JRuby lead Charles Nutter Spring AMQP 4.2.0-M1 Available Spring Integration 7.2.0-M1 Available Spring Batch 6.0.5 and 6.1.0-M1 available now Spring Boot 4.0.8 available now Spring Boot 4.1.1 available now Spring Boot 4.2.0-M1 available now This Week in Spring - August 18th, 2026 Spring Office Hours Podcast: S5E20 - The Developer's Guide to AI with Danny Thompson A Bootiful Podcast: Redouble AI CTO and founder Andrey Santrosyan This Week in Spring - August 11th, 2026 A Bootiful Podcast: Data guru Gregory Green on RabbitMQ, Valkey, Gemfire, Data Flow, and more This Week in Spring - August 4th, 2026 A Bootiful Podcast: Spring Boot founder and lead Phil Webb This Week in Spring - July 28th, 2026 Spring Office Hours Podcast: S5E19 - Docker, Compose, Testcontainers, Oh My! A Bootiful Podcast: Java Developer Advocate Billy Korando on Java 27 and Beyond This Week in Spring - July 21st, 2026 A Bootiful Podcast: Russ Miles on Safer, More Productive Interactions with AI This Week in Spring - July 14th, 2026 Spring Office Hours Podcast: S5E18 - The Latest from OpenAI, Anthropic and Spring AI 2.0 A Bootiful Podcast: Spring Boot legend Moritz Halbritter on the latest and greatest in Spring Boot 4 and 4.1 This Week in Spring - July 7th, 2026 A New Home for Spring Cloud Contract: Transitioning to Stubborn.sh Spring Office Hours Podcast: S5E17 - Spring Boot 4.1 with Phil Webb A Bootiful Podcast: Sébastien Deleuze on the latest-and-greatest in Spring AI and Spring Framework
Spring Cloud 2025.1.3 (aka Oakwood) Has Been Released
ryanjbaxter · 2026-08-20 · via Spring

On behalf of the community, I am pleased to announce that the General Availability (RELEASE) of the Spring Cloud 2025.1.3 Release Train is available today. The release can be found in Maven Central. You can check out the 2025.1.3 release notes for more information.

Notable Changes in the 2025.1.3 Release Train

This release is based on Spring Boot 4.0.8.

Spring Cloud Circuitbreaker

  • Default configuration of TimeLimiterConfig in Resilience4JCircuitBreakerFactory is no longer used (#284)

Spring Cloud Commons

  • Fix for CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint
  • Bouncycastle has been upgraded to 1.85.2 and Spring Cloud Commons now uses the Bouncycastle BOM in 34d9ec2
  • Do not recursively try to reset configuration properties for library types (#1699)
  • Skip resetting beans to default vaules if there is no default constructor (#1701)
  • Autowire beans when rebinding (#1720)

Spring Cloud Config

  • Fix for CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
  • Fix for CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
  • Fix for CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
  • Fix for CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service
  • Support Git-style searchPaths with wildcards in AWS S3 buckets (#2958)

Spring Cloud Consul

  • Add required parameter annotations to eventList (#1000)

Spring Cloud Function

  • Fix for CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
  • Fix for CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
  • Fix for CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
  • Fix for CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
  • Fix for CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
  • Fix for CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure

Spring Cloud Gateway

  • Fix for CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC
  • Add MVC retry backoff support (#4225)

Spring Cloud Stream

  • Fix for CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
  • Fix for CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
  • Fix for CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
  • Fix for CVE-2026-59305 — Partition interceptor may be improperly added while sending message
  • Fix for CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream

The following modules were updated as part of 2025.1.3:

Module Version Issues
Spring Cloud Build 5.0.3 (issues)
Spring Cloud Bus 5.0.3 (issues)
Spring Cloud Circuitbreaker 5.0.3 (issues)
Spring Cloud Commons 5.0.3 (issues)
Spring Cloud Config 5.0.5 (issues)
Spring Cloud Consul 5.0.3 (issues)
Spring Cloud Function 5.0.4 (issues)
Spring Cloud Gateway 5.0.3 (issues)
Spring Cloud Kubernetes 5.0.3 (issues)
Spring Cloud Openfeign 5.0.3 (issues)
Spring Cloud Starter Build 2025.1.3 (issues)
Spring Cloud Stream 5.0.3 (issues)

As always, we welcome feedback on GitHub, on Gitter, on Stack Overflow, or on Twitter.

To get started with Maven with a BOM (dependency management only):


<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.springframework.cloud</groupId>
            <artifactId>spring-cloud-dependencies</artifactId>
            <version>2025.1.3</version>
            <type>pom</type>
            <scope>import</scope>
        </dependency>
    </dependencies>
</dependencyManagement>
<dependencies>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-config</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId>
    </dependency>
    ...
</dependencies>

or with Gradle:

buildscript {
dependencies {
classpath "io.spring.gradle:dependency-management-plugin:1.0.2.RELEASE"
}
}



apply plugin: "io.spring.dependency-management"

dependencyManagement {
imports {
mavenBom 'org.springframework.cloud:spring-cloud-dependencies:2025.1.3'
}
}

dependencies {
compile 'org.springframework.cloud:spring-cloud-starter-config'
compile 'org.springframework.cloud:spring-cloud-starter-netflix-eureka-client'
...
}