CVE-2025-41249

EUVD-2025-29537
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.

Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.

You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.

This CVE is published in conjunction with  CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
vmwareCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38.37%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
vmwarespring
6.2.0 ≤
𝑥
< 6.2.11
CNA
vmwarespring
6.1.0 ≤
𝑥
< 6.1.23
CNA
vmwarespring
5.3.0 ≤
𝑥
< 5.3.45
CNA
Debian logo
Debian Releases
Debian Product
Codename
libspring-java
bookworm
unimportant
bullseye
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-java
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage