CVE-2025-41248
published 2025-09-16CVE-2025-41248: The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
35.1th percentile
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| vmware | spring_framework | >= 5.3.x < 5.3.45 | 5.3.45 |
| vmware | spring_framework | >= 6.1.x < 6.1.23 | 6.1.23 |
| vmware | spring_framework | >= 6.2.x < 6.2.11 | 6.2.11 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Security annotation detection mechanism has authorization bypass
ghsa·2025-09-16·CVSS 7.5
CVE-2025-41248 [HIGH] CWE-289 Spring Security annotation detection mechanism has authorization bypass
Spring Security annotation detection mechanism has authorization bypass
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .
GHSA
Spring Framework annotation detection mechanism may result in improper authorization
ghsa·2025-09-16·CVSS 7.5
CVE-2025-41249 [HIGH] CWE-285 Spring Framework annotation detection mechanism may result in improper authorization
Spring Framework annotation detection mechanism may result in improper authorization
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
OSV
Spring Security annotation detection mechanism has authorization bypass
osv·2025-09-16·CVSS 7.5
CVE-2025-41248 [HIGH] Spring Security annotation detection mechanism has authorization bypass
Spring Security annotation detection mechanism has authorization bypass
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .
OSV
Spring Framework annotation detection mechanism may result in improper authorization
osv·2025-09-16·CVSS 7.5
CVE-2025-41249 [HIGH] Spring Framework annotation detection mechanism may result in improper authorization
Spring Framework annotation detection mechanism may result in improper authorization
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
OSV
CVE-2025-41249: The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe
osv·2025-09-16·CVSS 7.5
CVE-2025-41249 [HIGH] CVE-2025-41249: The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) — CVE-2025-41248
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-41248 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) — CVE-2025-41248
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Spring Security) vulnerability
CVE: CVE-2025-41248
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Red Hat
org.springframework.security/spring-security-core: Spring Security authorization bypass
vendor_redhat·2025-09-16·CVSS 7.5
CVE-2025-41248 [HIGH] CWE-289 org.springframework.security/spring-security-core: Spring Security authorization bypass
org.springframework.security/spring-security-core: Spring Security authorization bypass
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .
The Spring Security annota
Red Hat
org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
vendor_redhat·2025-09-16·CVSS 7.5
CVE-2025-41249 [HIGH] CWE-863 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
The Spring Framework annotation detection mechanism may not correctly re
Debian
CVE-2025-41249: libspring-java - The Spring Framework annotation detection mechanism may not correctly resolve an...
vendor_debian·2025·CVSS 7.5
CVE-2025-41249 [HIGH] CVE-2025-41249: libspring-java - The Spring Framework annotation detection mechanism may not correctly resolve an...
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
2025-09-16
Published