cbcvebase.
CVE-2025-22235
published 2025-04-28

CVE-2025-22235: EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your…

PriorityP341high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.36%
28.0th percentile
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed.

Your application may be affected by this if all the following conditions are met:

* You use Spring Security
* EndpointRequest.to() has been used in a Spring Security chain configuration
* The endpoint which EndpointRequest references is disabled or not exposed via web
* Your application handles requests to /null and this path needs protection


You are not affected if any of the following is true:

* You don't use Spring Security
* You don't use EndpointRequest.to()
* The endpoint which EndpointRequest.to() refers to is enabled and is exposed
* Your application does not handle requests to /null or this path does not need protection

Affected

8 ranges
VendorProductVersion rangeFixed in
msrccbl2_wireshark_3.4.14-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
springspring_boot>= 2.7.x < 2.7.252.7.25
springspring_boot>= 3.1.x < 3.1.163.1.16
springspring_boot>= 3.2.x < 3.2.143.2.14
springspring_boot>= 3.3.x < 3.3.113.3.11
springspring_boot>= 3.4.x < 3.4.53.4.5

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.3HIGH
vendor_msrc7.5HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.