CVE-2025-41235 describes a critical vulnerability in Spring Cloud Gateway Server where it improperly forwards X-Forwarded-For and Forwarded headers from untrusted proxies, potentially leading to security bypasses or misattribution. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with low attack complexity, allowing for high impact on integrity without requiring user interaction or privileges. Currently, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not yet widely known or exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| VMware | Spring Cloud Gateway Server MVC | >= 4.1.7 - 4.2.2, 4.3.0-{M1, M2, RC1}, < 4.3.0, 4.2.3, 4.1.8CNA affecteddefault affected | |
| VMware | Spring Cloud Gateway | >= 2.2.10.RELEASE - 4.2.2, 4.3.0-{M1, M2, RC1}, < 4.3.0, 4.2.3, 4.1.8, 4.0.12, 3.1.10CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.