Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2025-41243: Spring Cloud Gateway Server Webflux could be exploited

CVE-2025-41243 · published 1 day ago
Summary

The Spring Cloud Gateway Server Webflux library used in your applications may allow an attacker to run unauthorized code. This can affect any system that includes the library from the listed packages. Apply the updated versions provided by Root as soon as possible to protect your environment.

What to do
  • Update springframework org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.2.5.
  • Update springframework org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.1.
  • Update org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.0-aikido.1.
  • Update io.root.org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.0-root.io.1.
Affected software
Ecosystem VendorProductAffected versions
maven springframework org.springframework.cloud:spring-cloud-gateway-server-webflux >= 3.1.0, <= 3.1.10
>= 4.0.0, <= 4.1.10
>= 4.2.0, < 4.2.5
>= 4.3.0, < 4.3.1
Fix: upgrade to 4.2.5
Root:Maven – org.springframework.cloud:spring-cloud-gateway-server-webflux < 4.3.0-aikido.1
Fix: upgrade to 4.3.0-aikido.1
Root:Maven – io.root.org.springframework.cloud:spring-cloud-gateway-server-webflux < 4.3.0-root.io.1
Fix: upgrade to 4.3.0-root.io.1
Original advisory text
CVE-2025-41243 in org.springframework.cloud:spring-cloud-gateway-server-webflux - Patched by Root
Root has patched CVE-2025-41243 in the org.springframework.cloud:spring-cloud-gateway-server-webflux package for Root:Maven. Multiple fixed versions available.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
4% chance of attack within 30 days
Type
CWE-94Code Injection
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta