CVE-2025-41249
Last modified
CVE-2025-41249 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41249?
How severe is CVE-2025-41249?
How do I fix CVE-2025-41249?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41242Spring Framework MVC applications can be vulnerable to a “Pa…5.9
- CVE-2025-41243Spring Cloud Gateway Server Webflux may be vulnerable to Spr…10
- CVE-2025-41244VMware Aria Operations and VMware Tools contain a local priv…7.8
- CVE-2025-41245VMware Aria Operations contains an information disclosure vu…4.9
- CVE-2025-41246VMware Tools for Windows contains an improper authorisation …7.6
- CVE-2025-41248The Spring Security annotation detection mechanism may not c…7.5
- CVE-2025-4125Delta Electronics ISPSoft version 3.20 is vulnerable to an O…9.8
- CVE-2025-41250VMware vCenter contains an SMTP header injection vulnerabili…8.5
- CVE-2025-41251VMware NSX contains a weak password recovery mechanism vulne…8.1
- CVE-2025-41252Description: VMware NSX contains a username enumeration vuln…7.5
- CVE-2025-41253The following versions of Spring Cloud Gateway Server Webflu…7.5
- CVE-2025-41254STOMP over WebSocket applications may be vulnerable to a sec…4.3
Are you affected by CVE-2025-41249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
