The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vmware
Vmware spring Framework |
|
Vendors & Products |
Vmware
Vmware spring Framework |
Tue, 16 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-285 | |
Metrics |
ssvc
|
Tue, 16 Sep 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 . | |
Title | CVE-2025-41249: Spring Framework Annotation Detection Vulnerability | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: vmware
Published: 2025-09-16T10:15:34.118Z
Updated: 2025-09-16T19:29:37.532Z
Reserved: 2025-04-16T09:30:25.625Z
Link: CVE-2025-41249

Updated: 2025-09-16T19:29:34.207Z

Status : Awaiting Analysis
Published: 2025-09-16T11:15:30.887
Modified: 2025-09-16T20:15:35.127
Link: CVE-2025-41249
