The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Jan 21, 2026 | Jan 20, 2026 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 38792753 for version 14.1.2.0.0.Apply the Patch Set Update (PSU) 38793419 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 38792523 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 38823015 for version 15.1.1.0.0. | Jan 23, 2026 | Sep 16, 2025 |
| Red Hat Jboss Eap | — | — | Sep 18, 2025 | Sep 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub