Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
ID: 1065e6bd-7c7c-508c-8c20-98751ff4c460
STIX ID: report--1065e6bd-7c7c-508c-8c20-98751ff4c460
Feed Name: securityonline.info
VMware Tanzu’s Spring team released patches for two vulnerabilities: CVE-2025-41253 in Spring Cloud Gateway (WebFlux) allowing remote SpEL misuse that can expose environment variables and system properties when actuator gateway endpoints are exposed and route definitions are controllable, and CVE-2025-41254 in Spring Framework’s STOMP over WebSocket allowing CSRF-bypass message injection; affected versions across multiple 3.x–6.x lines have fixes available and Spring advises securing or disabling exposed actuator gateway endpoints as an interim mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
