Security
This release train contains fixes for 17 CVEs across 5 modules.
Spring Cloud Commons 5.0.3
- CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint
Spring Cloud Config 5.0.5
- CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
- CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
- CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
- CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service
Spring Cloud Function 5.0.4
- CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
- CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
- CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
- CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
- CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
- CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure
Spring Cloud Gateway 5.0.3
- CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC
Spring Cloud Stream 5.0.3
- CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
- CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
- CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
- CVE-2026-59305 — Partition interceptor may be improperly added while sending message
- CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream
What's Included
- Spring Cloud Build
5.0.3(issues) - Spring Cloud Function
5.0.4(issues) - Spring Cloud Stream
5.0.3(issues) - Spring Cloud Commons
5.0.3(issues) - Spring Cloud Bus
5.0.3(issues) - Spring Cloud Task
5.0.2(issues) - Spring Cloud Config
5.0.5(issues) - Spring Cloud Netflix
5.0.2(issues) - Spring Cloud Openfeign
5.0.3(issues) - Spring Cloud Consul
5.0.3(issues) - Spring Cloud Circuitbreaker
5.0.3(issues) - Spring Cloud Gateway
5.0.3(issues) - Spring Cloud Zookeeper
5.0.2(issues) - Spring Cloud Kubernetes
5.0.3(issues) - Spring Cloud Vault
5.0.2(issues)
What's Changed
- Bump com.github.jknack:handlebars from 4.5.1 to 4.5.2 by @dependabot[bot] in #520
- Bump com.github.jknack:handlebars from 4.5.1 to 4.5.2 by @dependabot[bot] in #521
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in #522
- Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs by @dependabot[bot] in #524
- Bump com.github.jknack:handlebars from 4.5.2 to 4.5.3 by @dependabot[bot] in #528
- Bump com.github.jknack:handlebars from 4.5.2 to 4.5.3 by @dependabot[bot] in #527
- Bump com.github.jknack:handlebars from 4.5.3 to 4.5.4 by @dependabot[bot] in #533
- Bump com.github.jknack:handlebars from 4.5.3 to 4.5.4 by @dependabot[bot] in #532
- Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs by @dependabot[bot] in #534
Full Changelog: v2025.1.2...v2025.1.3