Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vulnerable when all the following are true:
* The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable).
* Spring Boot actuator is a dependency.
* The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway.
* The actuator endpoints are available to attackers.
* The actuator endpoints are unsecured.
References
Link | Resource |
---|---|
https://spring.io/security/cve-2025-41243 |
Configurations
No configuration.
History
16 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-16 15:15
Updated : 2025-09-17 14:18
NVD link : CVE-2025-41243
Mitre link : CVE-2025-41243
CVE.ORG link : CVE-2025-41243
JSON object : View
Products Affected
No product.