CVE-2025-41253 describes a vulnerability in Spring Cloud Gateway Server Webflux that allows attackers to expose environment variables and system properties. This occurs when an untrusted party can create routes using Spring Expression Language (SpEL) and the gateway's actuator web endpoints are enabled, exposed, and unsecured. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact, but no integrity or availability impact. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one mention and one media article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| VMware | Spring Cloud Gateway Server Webflux | 3.1.x, 4.0.x, 4.1.x, 4.2.x, 4.3.xCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
Oct 16, 2025Using Spring Expression Language To Expose Environment Variables and System Properties
Oct 15, 2025CVE-2025-41253: Using Spring Expression Language To Expose Environment Variables and System Properties
Oct 15, 2025Using Spring Expression Language To Expose Environment Variables and System Properties
Oct 15, 2025