Visit NES for Spring Home Page

Spring Cloud Stream 4.2.x Release Notes

3 versions

Comprehensive release notes and changelog for Spring Cloud Stream 4.2.x, including security patches, bug fixes, and feature updates across all supported versions.

Sep 1, 2026
Latest: 4.2.6
5 Patched Vulnerabilities
VEX Statements

September 2026

Full Version:
4.2.3-spring-cloud-stream-4.2.6

Security Fixes

  • Evicting a dynamic destination from StreamBridge's channel cache now also removes its generated binding properties, so the bindings map can no longer grow past the configured cache limit (low severity, CVE-2026-59303).
  • Queue and exchange names are now percent-encoded as single path segments by RabbitBindingCleaner, so a crafted name can no longer alter the RabbitMQ management API deletion path it is interpolated into (low severity, CVE-2026-59302).
  • Repeated sends to a cached partitioned destination no longer register duplicate DefaultPartitioningInterceptor instances, because FunctionConfiguration now checks the output channel for an existing one before adding another (low severity, CVE-2026-59305).
  • OriginalContentTypeResolver now evicts the eldest entry once its parsed MIME type cache exceeds 100 entries, so distinct inbound content type headers can no longer grow it without limit for the resolver's lifetime (low severity, CVE-2026-59304).
  • java.net is no longer one of BinderHeaderMapper's default trusted packages, so JSON-encoded Kafka headers naming java.net types are no longer deserialized without an explicit application trust decision (low severity, CVE-2026-59306).

Dependency Upgrades

  • Spring Cloud Build (NES) 4.2.4-spring-cloud-build-4.2.7
  • Spring Cloud Function (NES) 4.2.4-spring-cloud-function-4.2.8

June 2026

4.2.5

Released Jun 17, 2026
Full Version:
4.2.3-spring-cloud-stream-4.2.5

Dependency Upgrades

  • Spring Cloud Build (NES) 4.2.4-spring-cloud-build-4.2.6
  • Spring Cloud Function (NES) 4.2.4-spring-cloud-function-4.2.7

February 2026

4.2.4

Released Feb 4, 2026
Full Version:
4.2.3-spring-cloud-stream-4.2.4

Notes

  • This release originates from the open‑source Spring Cloud Stream repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Cloud Stream 4.2.3.

Dependency Upgrades

  • Spring Cloud Build (NES) 4.2.4-spring-cloud-build-4.2.5
  • Spring Cloud Function (NES) 4.2.4-spring-cloud-function-4.2.5

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.