Spring Cloud 2025.1.3 (aka Oakwood) Has Been Released

Releases | Ryan Baxter | August 20, 2026 | 3 min read | ...

On behalf of the community, I am pleased to announce that the General Availability (RELEASE) of the Spring Cloud 2025.1.3 Release Train is available today. The release can be found in Maven Central. You can check out the 2025.1.3 release notes for more information.

Notable Changes in the 2025.1.3 Release Train

This release is based on Spring Boot 4.0.8.

Spring Cloud Circuitbreaker

  • Default configuration of TimeLimiterConfig in Resilience4JCircuitBreakerFactory is no longer used (#284)

Spring Cloud Commons

  • Fix for CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint
  • Bouncycastle has been upgraded to 1.85.2 and Spring Cloud Commons now uses the Bouncycastle BOM in 34d9ec2
  • Do not recursively try to reset configuration properties for library types (#1699)
  • Skip resetting beans to default vaules if there is no default constructor (#1701)
  • Autowire beans when rebinding (#1720)

Spring Cloud Config

  • Fix for CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
  • Fix for CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
  • Fix for CVE-2026-47894 — Spring Cloud Config Server Native Environment Repository Exposure
  • Fix for CVE-2026-59315 — Spring Cloud Config Monitor Denial of Service
  • Support Git-style searchPaths with wildcards in AWS S3 buckets (#2958)

Spring Cloud Consul

  • Add required parameter annotations to eventList (#1000)

Spring Cloud Function

  • Fix for CVE-2026-59291 — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
  • Fix for CVE-2026-59297 — Spring Cloud Function can incorrectly determine if URI is secure
  • Fix for CVE-2026-59298 — Potential for improper filtering of HTTP headers in Spring Cloud Function
  • Fix for CVE-2026-59299 — Composition lookup can potentially poison base function in Spring Cloud Function
  • Fix for CVE-2026-59300 — Potential for logging sensitive data in Spring Cloud Function AWS
  • Fix for CVE-2026-59301 — Potential for logging sensitive data in Spring Cloud Function Azure

Spring Cloud Gateway

  • Fix for CVE-2026-47879 — Spring Cloud Gateway SSRF and native file access with gRPC
  • Add MVC retry backoff support (#4225)

Spring Cloud Stream

  • Fix for CVE-2026-59302 — Potential for logging sensitive data in Spring Cloud Stream
  • Fix for CVE-2026-59303 — Dynamic destination cache size is not properly bound in Spring Cloud Stream
  • Fix for CVE-2026-59304 — Improper caching of the original content type in Spring Cloud Stream Avro
  • Fix for CVE-2026-59305 — Partition interceptor may be improperly added while sending message
  • Fix for CVE-2026-59306 — Potential for deserialization of untrusted types in Spring Cloud Stream

The following modules were updated as part of 2025.1.3:

Module Version Issues
Spring Cloud Build 5.0.3 (issues)
Spring Cloud Bus 5.0.3 (issues)
Spring Cloud Circuitbreaker 5.0.3 (issues)
Spring Cloud Commons 5.0.3 (issues)
Spring Cloud Config 5.0.5 (issues)
Spring Cloud Consul 5.0.3 (issues)
Spring Cloud Function 5.0.4 (issues)
Spring Cloud Gateway 5.0.3 (issues)
Spring Cloud Kubernetes 5.0.3 (issues)
Spring Cloud Openfeign 5.0.3 (issues)
Spring Cloud Starter Build 2025.1.3 (issues)
Spring Cloud Stream 5.0.3 (issues)

As always, we welcome feedback on GitHub, on Gitter, on Stack Overflow, or on Twitter.

To get started with Maven with a BOM (dependency management only):


<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.springframework.cloud</groupId>
            <artifactId>spring-cloud-dependencies</artifactId>
            <version>2025.1.3</version>
            <type>pom</type>
            <scope>import</scope>
        </dependency>
    </dependencies>
</dependencyManagement>
<dependencies>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-config</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId>
    </dependency>
    ...
</dependencies>

or with Gradle:

buildscript {
dependencies {
classpath "io.spring.gradle:dependency-management-plugin:1.0.2.RELEASE"
}
}



apply plugin: "io.spring.dependency-management"

dependencyManagement {
imports {
mavenBom 'org.springframework.cloud:spring-cloud-dependencies:2025.1.3'
}
}

dependencies {
compile 'org.springframework.cloud:spring-cloud-starter-config'
compile 'org.springframework.cloud:spring-cloud-starter-netflix-eureka-client'
...
}

Get the Spring newsletter

Stay connected with the Spring newsletter

Subscribe

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all