Skip to content

build(deps): bump org.springframework.cloud:spring-cloud-dependencies from 2025.0.3 to 2025.1.3 in /backend in the safe-non-major-updates group across 1 directory - #18

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/backend/safe-non-major-updates-d01e2d99a5
Open

build(deps): bump org.springframework.cloud:spring-cloud-dependencies from 2025.0.3 to 2025.1.3 in /backend in the safe-non-major-updates group across 1 directory#18
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/backend/safe-non-major-updates-d01e2d99a5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 16, 2026

Copy link
Copy Markdown

Bumps the safe-non-major-updates group with 1 update in the /backend directory: org.springframework.cloud:spring-cloud-dependencies.

Updates org.springframework.cloud:spring-cloud-dependencies from 2025.0.3 to 2025.1.3

Release notes

Sourced from org.springframework.cloud:spring-cloud-dependencies's releases.

v2025.1.3

Security

This release train contains fixes for 17 CVEs across 5 modules.

Spring Cloud Commons 5.0.3

  • CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint

Spring Cloud Config 5.0.5

  • CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
  • CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
  • CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
  • CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service

Spring Cloud Function 5.0.4

  • CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
  • CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
  • CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
  • CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
  • CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
  • CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure

Spring Cloud Gateway 5.0.3

  • CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC

Spring Cloud Stream 5.0.3

  • CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
  • CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
  • CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
  • CVE-2026-59305 — Partition interceptor may be improperly added while sending message
  • CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream

What's Included

  • Spring Cloud Build 5.0.3 (issues)
  • Spring Cloud Function 5.0.4 (issues)
  • Spring Cloud Stream 5.0.3 (issues)
  • Spring Cloud Commons 5.0.3 (issues)
  • Spring Cloud Bus 5.0.3 (issues)
  • Spring Cloud Task 5.0.2 (issues)
  • Spring Cloud Config 5.0.5 (issues)
  • Spring Cloud Netflix 5.0.2 (issues)
  • Spring Cloud Openfeign 5.0.3 (issues)
  • Spring Cloud Consul 5.0.3 (issues)
  • Spring Cloud Circuitbreaker 5.0.3 (issues)
  • Spring Cloud Gateway 5.0.3 (issues)

... (truncated)

Commits
  • d52d95a Release 2025.1.3
  • 5ba4ec5 Initialize commercial release branch
  • 7e855d0 Update versions for 2025.1.3-INTERNAL-SNAPSHOT
  • 22ebee1 Add commercial release CI files [skip actions]
  • 3c1c981 Merge pull request #534 from spring-cloud/dependabot/npm_and_yarn/docs/main/s...
  • b79bd77 Bump @​springio/antora-extensions from 1.14.12 to 1.14.13 in /docs
  • 65eb111 Use canonical deploy-docs trigger workflow [skip actions]
  • 7501938 Merge pull request #532 from spring-cloud/dependabot/maven/main/com.github.jk...
  • e3b2779 Merge pull request #533 from spring-cloud/dependabot/maven/com.github.jknack-...
  • 791fbef Bump com.github.jknack:handlebars from 4.5.3 to 4.5.4
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Aug 16, 2026
Bumps the safe-non-major-updates group with 1 update in the /backend directory: [org.springframework.cloud:spring-cloud-dependencies](https://github.com/spring-cloud/spring-cloud-release).


Updates `org.springframework.cloud:spring-cloud-dependencies` from 2025.0.3 to 2025.1.3
- [Release notes](https://github.com/spring-cloud/spring-cloud-release/releases)
- [Changelog](https://github.com/spring-cloud/spring-cloud-release/blob/main/release-train-settings.xml)
- [Commits](spring-cloud/spring-cloud-release@v2025.0.3...v2025.1.3)

---
updated-dependencies:
- dependency-name: org.springframework.cloud:spring-cloud-dependencies
  dependency-version: 2025.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-non-major-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump org.springframework.cloud:spring-cloud-dependencies from 2025.0.3 to 2025.1.2 in /backend in the safe-non-major-updates group build(deps): bump org.springframework.cloud:spring-cloud-dependencies from 2025.0.3 to 2025.1.3 in /backend in the safe-non-major-updates group across 1 directory Aug 23, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/backend/safe-non-major-updates-d01e2d99a5 branch from 2afe34c to 21528fb Compare August 23, 2026 19:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants