Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2025-41243: Spring Cloud Gateway Server Webflux could be exploited
CVE-2025-41243 · published 1 day ago
Summary
The Spring Cloud Gateway Server Webflux library used in your applications may allow an attacker to run unauthorized code. This can affect any system that includes the library from the listed packages. Apply the updated versions provided by Root as soon as possible to protect your environment.
What to do
- Update springframework org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.2.5.
- Update springframework org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.1.
- Update org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.0-aikido.1.
- Update io.root.org.springframework.cloud:spring-cloud-gateway-server-webflux to version 4.3.0-root.io.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | springframework | org.springframework.cloud:spring-cloud-gateway-server-webflux |
>= 3.1.0, <= 3.1.10 >= 4.0.0, <= 4.1.10 >= 4.2.0, < 4.2.5 >= 4.3.0, < 4.3.1 Fix: upgrade to 4.2.5
|
| Root:Maven | – | org.springframework.cloud:spring-cloud-gateway-server-webflux |
< 4.3.0-aikido.1 Fix: upgrade to 4.3.0-aikido.1
|
| Root:Maven | – | io.root.org.springframework.cloud:spring-cloud-gateway-server-webflux |
< 4.3.0-root.io.1 Fix: upgrade to 4.3.0-root.io.1
|
Original advisory text
CVE-2025-41243 in org.springframework.cloud:spring-cloud-gateway-server-webflux - Patched by Root
Root has patched CVE-2025-41243 in the org.springframework.cloud:spring-cloud-gateway-server-webflux package for Root:Maven. Multiple fixed versions available.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-94Code Injection
CWE-917Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta