Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
Critical severity
GitHub Reviewed
Published
Sep 16, 2025
to the GitHub Advisory Database
•
Updated Sep 16, 2025
Package
Affected versions
>= 3.1.0, <= 3.1.10
>= 4.0.0, <= 4.1.10
>= 4.2.0, < 4.2.5
>= 4.3.0, < 4.3.1
Patched versions
4.2.5
4.3.1
Description
Published by the National Vulnerability Database
Sep 16, 2025
Published to the GitHub Advisory Database
Sep 16, 2025
Reviewed
Sep 16, 2025
Last updated
Sep 16, 2025
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification.
An application should be considered vulnerable when all the following are true:
References