Skip to content

fix(deps): update dependency org.springframework.cloud:spring-cloud-dependencies to v2025.1.3 - #5643

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/spring-cloud
Aug 29, 2026
Merged

fix(deps): update dependency org.springframework.cloud:spring-cloud-dependencies to v2025.1.3#5643
renovate[bot] merged 1 commit into
masterfrom
renovate/spring-cloud

Conversation

@renovate

@renovate renovate Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.springframework.cloud:spring-cloud-dependencies (source) 2025.1.22025.1.3 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

spring-cloud/spring-cloud-release (org.springframework.cloud:spring-cloud-dependencies)

v2025.1.3

Security

This release train contains fixes for 17 CVEs across 5 modules.

Spring Cloud Commons 5.0.3

  • CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint

Spring Cloud Config 5.0.5

  • CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
  • CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
  • CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
  • CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service

Spring Cloud Function 5.0.4

  • CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
  • CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
  • CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
  • CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
  • CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
  • CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure

Spring Cloud Gateway 5.0.3

  • CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC

Spring Cloud Stream 5.0.3

  • CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
  • CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
  • CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
  • CVE-2026-59305 — Partition interceptor may be improperly added while sending message
  • CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream

What's Included

  • Spring Cloud Build 5.0.3 (issues)
  • Spring Cloud Function 5.0.4 (issues)
  • Spring Cloud Stream 5.0.3 (issues)
  • Spring Cloud Commons 5.0.3 (issues)
  • Spring Cloud Bus 5.0.3 (issues)
  • Spring Cloud Task 5.0.2 (issues)
  • Spring Cloud Config 5.0.5 (issues)
  • Spring Cloud Netflix 5.0.2 (issues)
  • Spring Cloud Openfeign 5.0.3 (issues)
  • Spring Cloud Consul 5.0.3 (issues)
  • Spring Cloud Circuitbreaker 5.0.3 (issues)
  • Spring Cloud Gateway 5.0.3 (issues)
  • Spring Cloud Zookeeper 5.0.2 (issues)
  • Spring Cloud Kubernetes 5.0.3 (issues)
  • Spring Cloud Vault 5.0.2 (issues)

What's Changed

Full Changelog: spring-cloud/spring-cloud-release@v2025.1.2...v2025.1.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the type: dependency-upgrade Pull requests that update a dependency file label Aug 29, 2026
@renovate
renovate Bot requested a review from a team as a code owner August 29, 2026 02:52
@renovate renovate Bot added the type: dependency-upgrade Pull requests that update a dependency file label Aug 29, 2026
@renovate
renovate Bot enabled auto-merge (squash) August 29, 2026 02:53
@renovate
renovate Bot merged commit 7698a75 into master Aug 29, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/spring-cloud branch August 29, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: dependency-upgrade Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants