This page lists Spring advisories.
CVE-2025-41254: Spring Framework STOMP CSRF Vulnerability
Description
STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.
Affected Spring Products and Versions
Spring Framework:
- 6.2.0 - 6.2.11
- 6.1.0 - 6.1.23
- 6.0.x - 6.0.29
- 5.3.0 - 5.3.45
- Older, unsupported versions are also affected. …
CVE-2025-41253: Using Spring Expression Language To Expose Environment Variables and System Properties
Description
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers.
An application should be considered vulnerable when all the following are true:
- The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable).
- An admin or untrusted third party using Spring Expression Language (SpEL) to access environment variables or system properties via routes.
- An untrusted third party could create a route that uses SpEL to access environment variables or system properties if:
- The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via
management.endpoints.web.exposure.include=gatewayandmanagement.endpoint.gateway.enabled=trueormanagement.endpoint.gateway.access=unrestricte. - …
- The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via
CVE-2025-41249: Spring Framework Annotation Detection Vulnerability
CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized types
CVE-2025-41243: Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
Description
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vulnerable when all the following are true:
- The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable).
- Spring Boot actuator is a dependency.
- The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via
management.endpoints.web.exposure.include=gateway…
CVE-2025-41242: Path traversal vulnerability on non-compliant Servlet containers
Description
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container.
An application can be vulnerable when all the following are true:
- the application is deployed as a WAR or with an embedded Servlet container
- the Servlet container does not reject suspicious sequences
- the application serves static resources with Spring resource handling …
CVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP Client
CVE-2025-41234: RFD Attack via “Content-Disposition” Header Sourced from Request
CVE-2025-41235: Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
Reporting a vulnerability
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy