Visit NES for Spring Home Page

Spring Cloud Stream Binder Kafka 3.1.x Release Notes

3 versions

Comprehensive release notes and changelog for Spring Cloud Stream Binder Kafka 3.1.x, including security patches, bug fixes, and feature updates across all supported versions.

Sep 1, 2026
Latest: 3.1.9
1 Patched Vulnerability
VEX Statements

September 2026

3.1.9

Released Sep 1, 2026
Full Version:
3.1.6-spring-cloud-stream-3.1.9

Security Fixes

  • java.net is no longer one of BinderHeaderMapper's default trusted packages, so JSON-encoded Kafka headers naming java.net types are no longer deserialized without an explicit application trust decision (low severity, CVE-2026-59306).

Dependency Upgrades

  • Spring Cloud Build (NES) 3.0.5-spring-cloud-build-3.0.8
  • Spring Cloud Stream (NES) 3.1.6-spring-cloud-stream-3.1.9

June 2026

3.1.8

Released Jun 17, 2026
Full Version:
3.1.6-spring-cloud-stream-3.1.8

Dependency Upgrades

  • Spring Cloud Build (NES) 3.0.5-spring-cloud-build-3.0.7
  • Spring Cloud Stream (NES) 3.1.6-spring-cloud-stream-3.1.8

March 2026

3.1.7

Released Mar 11, 2026
Full Version:
3.1.6-spring-cloud-stream-3.1.7

Notes

  • This release originates from the open‑source Spring Cloud Stream Binder Kafka repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Cloud Stream Binder Kafka 3.1.6.

Dependency Upgrades

  • Spring Cloud Build (NES) 3.0.5-spring-cloud-build-3.0.6
  • Spring Cloud Stream (NES) 3.1.6-spring-cloud-stream-3.1.7

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.