Back to overview

CVE-2025-41243

CRITICAL
10.0
CVSS 3.1
Description
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable). * Spring Boot actuator is a dependency. * The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway. * The actuator endpoints are available to attackers. * The actuator endpoints are unsecured.

Metadata

CVE ID
CVE-2025-41243
State
PUBLISHED
Assigner
vmware
Reserved
2025-04-16 09:30 UTC
Published
2025-09-16 14:54 UTC
Last updated
2026-02-26 17:48 UTC
Primary CWE
CWE-917
CWE-917 Improper Neutralization of Special Elements used in …
Vendor / Product
Spring / Cloud Gateway
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Spring Cloud Gateway 4.3.x < 4.3.1, 4.2.x < 4.2.5, 4.1.x, 4.0.x < 4.1.11, 3.1.x < 3.1.11
Weakness (CWE)
CWESourceDescription
CWE-917 cna CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CWE-94 cna CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview