← Back to browse · API

CVE-2025-41243

Severity
CRITICAL
CVSS
10.0
EPSS
0.03311
Risk score
41.16
CISA KEV
No
PoC
No
Published
2025-09-16
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-29611, GHSA-Q2CJ-H8FW-Q4CC
Products
Spring:Cloud Gateway 3.1.x <3.1.11, Spring:Cloud Gateway 4.1.x, 4.0.x <4.1.11, Spring:Cloud Gateway 4.2.x <4.2.5, Spring:Cloud Gateway 4.3.x <4.3.1
Sources
euvd EUVD-2025-29611

Description

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable). * Spring Boot actuator is a dependency. * The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway. * The actuator endpoints are available to attackers. * The actuator endpoints are unsecured.

References