Information disclosure in Spring Cloud Gateway - CVE-2025-41253
Published: October 16, 2025
Vulnerability identifier: #VU117304
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41253
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in Webflux. A remote attacker can use a specially crafted HTTP request to obtain environment variables and system properties.
Affected software
Spring Cloud Gateway
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Library Support for Spring
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Repository Function
Library Support for Spring
Oracle Communications Cloud Native Core Network Slice Selection Function
How to mitigate CVE-2025-41253
Install updates from vendor's website.
Spring Cloud Gateway - addressed in versions 3.1.12, 4.1.12, 4.2.6, 4.3.2
Library Support for Spring - addressed in versions 2.7.31, 3.2.19
Library Support for Spring - addressed in versions 2.7.31, 3.2.19
External References
Related Security Bulletins
- Information disclosure in Spring Cloud Gateway
- Multiple vulnerabilities in IBM Library Support for Spring
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function