#VU115570 Protection Mechanism Failure in Spring Security - CVE-2025-41248
Published: September 16, 2025
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the annotation detection mechanism does not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. A remote attacker can gain access to sensitive information.