Loading HuntDB...

CVE-2025-41248

HIGH
Published 2025-09-16T10:10:59.953Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-41248. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
7.5
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Description

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.

Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.

You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.

This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

2 posts
Reddit 2 hours, 49 minutes ago
falconupkid

CVE-2025-41248 & CVE-2025-41249: Vulnerabilities in Spring Framework, Spring Security Lead to Authorization Bypass, Expose Sensitive Data Spring Framework is a lightweight Java framework widely used for building scalable enterprise applications. It is often used in conjunction with Spring Security to enforce authorization and method-level access controls. Because many... **CVEs:** CVE-2022-22965,CVE-2025-41248,CVE-2025-41249,cve-2025-41248,cve-2025-41249 …

Also mentions: CVE-2022-22965
Reddit 4 hours, 46 minutes ago
crstux
Exploit PoC

🔥 Top 10 Trending CVEs (18/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-9708](https://nvd.nist.gov/vuln/detail/CVE-2025-9708)** - 📝 A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. …

2
2.0
View Original High Risk

References

Published: 2025-09-16T10:10:59.953Z
Last Modified: 2025-09-18T06:29:51.189Z
Copied to clipboard!