惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
Engineering at Meta
Engineering at Meta
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 司徒正美
I
InfoQ
S
SegmentFault 最新的问题
博客园 - 叶小钗
N
Netflix TechBlog - Medium
Y
Y Combinator Blog
IT之家
IT之家
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
月光博客
月光博客
The Cloudflare Blog
U
Unit 42
GbyAI
GbyAI
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog

Spring

A Bootiful Podcast: Joe Grandja on Spring Authorization Server, OAuth, and so much more Spring Modulith 2.2 M1, 2.1.1, 2.0.8, and 1.4.13 released This Week in Spring - August 25th, 2026 Spring AI 2.0.1 Available Now A Bootiful Podcast: JRuby lead Charles Nutter Spring AMQP 4.2.0-M1 Available Spring Integration 7.2.0-M1 Available Spring Batch 6.0.5 and 6.1.0-M1 available now Spring Boot 4.0.8 available now Spring Boot 4.1.1 available now Spring Boot 4.2.0-M1 available now This Week in Spring - August 18th, 2026 Spring Office Hours Podcast: S5E20 - The Developer's Guide to AI with Danny Thompson A Bootiful Podcast: Redouble AI CTO and founder Andrey Santrosyan This Week in Spring - August 11th, 2026 A Bootiful Podcast: Data guru Gregory Green on RabbitMQ, Valkey, Gemfire, Data Flow, and more This Week in Spring - August 4th, 2026 A Bootiful Podcast: Spring Boot founder and lead Phil Webb This Week in Spring - July 28th, 2026 Spring Office Hours Podcast: S5E19 - Docker, Compose, Testcontainers, Oh My! A Bootiful Podcast: Java Developer Advocate Billy Korando on Java 27 and Beyond This Week in Spring - July 21st, 2026 A Bootiful Podcast: Russ Miles on Safer, More Productive Interactions with AI This Week in Spring - July 14th, 2026 Spring Office Hours Podcast: S5E18 - The Latest from OpenAI, Anthropic and Spring AI 2.0 A Bootiful Podcast: Spring Boot legend Moritz Halbritter on the latest and greatest in Spring Boot 4 and 4.1 This Week in Spring - July 7th, 2026 A New Home for Spring Cloud Contract: Transitioning to Stubborn.sh Spring Office Hours Podcast: S5E17 - Spring Boot 4.1 with Phil Webb A Bootiful Podcast: Sébastien Deleuze on the latest-and-greatest in Spring AI and Spring Framework
Spring Cloud 2025.1.3 (aka Oakwood) Has Been Released
ryanjbaxter · 2026-08-20 · via Spring

On behalf of the community, I am pleased to announce that the General Availability (RELEASE) of the Spring Cloud 2025.1.3 Release Train is available today. The release can be found in Maven Central. You can check out the 2025.1.3 release notes for more information.

Notable Changes in the 2025.1.3 Release Train

This release is based on Spring Boot 4.0.8.

Spring Cloud Circuitbreaker

  • Default configuration of TimeLimiterConfig in Resilience4JCircuitBreakerFactory is no longer used (#284)

Spring Cloud Commons

  • Fix for CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint
  • Bouncycastle has been upgraded to 1.85.2 and Spring Cloud Commons now uses the Bouncycastle BOM in 34d9ec2
  • Do not recursively try to reset configuration properties for library types (#1699)
  • Skip resetting beans to default vaules if there is no default constructor (#1701)
  • Autowire beans when rebinding (#1720)

Spring Cloud Config

  • Fix for CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
  • Fix for CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
  • Fix for CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
  • Fix for CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service
  • Support Git-style searchPaths with wildcards in AWS S3 buckets (#2958)

Spring Cloud Consul

  • Add required parameter annotations to eventList (#1000)

Spring Cloud Function

  • Fix for CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
  • Fix for CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
  • Fix for CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
  • Fix for CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
  • Fix for CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
  • Fix for CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure

Spring Cloud Gateway

  • Fix for CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC
  • Add MVC retry backoff support (#4225)

Spring Cloud Stream

  • Fix for CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
  • Fix for CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
  • Fix for CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
  • Fix for CVE-2026-59305 — Partition interceptor may be improperly added while sending message
  • Fix for CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream

The following modules were updated as part of 2025.1.3:

Module Version Issues
Spring Cloud Build 5.0.3 (issues)
Spring Cloud Bus 5.0.3 (issues)
Spring Cloud Circuitbreaker 5.0.3 (issues)
Spring Cloud Commons 5.0.3 (issues)
Spring Cloud Config 5.0.5 (issues)
Spring Cloud Consul 5.0.3 (issues)
Spring Cloud Function 5.0.4 (issues)
Spring Cloud Gateway 5.0.3 (issues)
Spring Cloud Kubernetes 5.0.3 (issues)
Spring Cloud Openfeign 5.0.3 (issues)
Spring Cloud Starter Build 2025.1.3 (issues)
Spring Cloud Stream 5.0.3 (issues)

As always, we welcome feedback on GitHub, on Gitter, on Stack Overflow, or on Twitter.

To get started with Maven with a BOM (dependency management only):


<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.springframework.cloud</groupId>
            <artifactId>spring-cloud-dependencies</artifactId>
            <version>2025.1.3</version>
            <type>pom</type>
            <scope>import</scope>
        </dependency>
    </dependencies>
</dependencyManagement>
<dependencies>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-config</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId>
    </dependency>
    ...
</dependencies>

or with Gradle:

buildscript {
dependencies {
classpath "io.spring.gradle:dependency-management-plugin:1.0.2.RELEASE"
}
}



apply plugin: "io.spring.dependency-management"

dependencyManagement {
imports {
mavenBom 'org.springframework.cloud:spring-cloud-dependencies:2025.1.3'
}
}

dependencies {
compile 'org.springframework.cloud:spring-cloud-starter-config'
compile 'org.springframework.cloud:spring-cloud-starter-netflix-eureka-client'
...
}