Cross-site request forgery in Spring Framework - CVE-2025-41254

 

Cross-site request forgery in Spring Framework - CVE-2025-41254

Published: October 16, 2025


Vulnerability identifier: #VU117323
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-41254
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin in STOMP over WebSocket applications. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Spring Framework
IBM Process Mining
Oracle Middleware Common Libraries and Tools
Library Support for Spring
Oracle Financial Services Analytical Applications Infrastructure
Operational Decision Manager

How to mitigate CVE-2025-41254

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.46, 6.1.24, 6.2.12
IBM Process Mining - update to 2.1.0
Library Support for Spring - addressed in versions 2.7.31, 3.2.19
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 54, 8.11.1 Interim fix 53, 8.12.0.1 Interim fix 37, 9.0.0.1 Interim fix 22, 9.5.0.1 Interim fix 5

External References

Related Security Bulletins