Visit NES for Spring Home Page

Spring Cloud Gateway 4.3.x Release Notes

2 versions

Comprehensive release notes and changelog for Spring Cloud Gateway 4.3.x, including security patches, bug fixes, and feature updates across all supported versions.

Sep 1, 2026
Latest: 4.3.7
5 Patched Vulnerabilities
VEX Statements

September 2026

4.3.7

Released Sep 1, 2026
Full Version:
4.3.5-spring-cloud-gateway-4.3.7

Security Fixes

  • A route definition can no longer resolve its proto descriptor or proto schema from an arbitrary file or URL: JsonToGrpcGatewayFilterFactory now rejects both protoDescriptor and protoFile unless they resolve under classpath: or classpath*:. The single property spring.cloud.gateway.server.webflux.json-to-grpc.valid-proto-descriptor-prefixes can be used to widen the allowed locations for both fields (high severity, CVE-2026-47879).

Dependency Upgrades

  • Spring Cloud Build (NES) 4.3.4-spring-cloud-build-4.3.6
  • Spring Cloud CircuitBreaker (NES) 3.3.3-spring-cloud-circuitbreaker-3.3.5
  • Spring Cloud Commons (NES) 4.3.3-spring-cloud-commons-4.3.5
  • Spring Cloud Function (NES) 4.3.4-spring-cloud-function-4.3.6
  • Spring Cloud Stream (NES) 4.3.3-spring-cloud-stream-4.3.5

July 2026

4.3.6

Released Jul 13, 2026
Full Version:
4.3.5-spring-cloud-gateway-4.3.6

Notes

  • This release originates from the open‑source Spring Cloud Gateway repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Cloud Gateway 4.3.5.

Dependency Upgrades

  • Spring Cloud Build (NES) 4.3.4-spring-cloud-build-4.3.5
  • Spring Cloud CircuitBreaker (NES) 3.3.3-spring-cloud-circuitbreaker-3.3.4
  • Spring Cloud Commons (NES) 4.3.3-spring-cloud-commons-4.3.4
  • Spring Cloud Function (NES) 4.3.4-spring-cloud-function-4.3.5
  • Spring Cloud Stream (NES) 4.3.3-spring-cloud-stream-4.3.4

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.