Information disclosure in Spring Cloud Gateway - CVE-2025-41253

 

Information disclosure in Spring Cloud Gateway - CVE-2025-41253

Published: October 16, 2025


Vulnerability identifier: #VU117304
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41253
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Webflux. A remote attacker can use a specially crafted HTTP request to obtain environment variables and system properties. 


Affected software

Spring Cloud Gateway
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Library Support for Spring
Oracle Communications Cloud Native Core Network Slice Selection Function

How to mitigate CVE-2025-41253

Install updates from vendor's website.

Spring Cloud Gateway - addressed in versions 3.1.12, 4.1.12, 4.2.6, 4.3.2
Library Support for Spring - addressed in versions 2.7.31, 3.2.19

External References

Related Security Bulletins