The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
History

Thu, 18 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
References
Metrics threat_severity

None

threat_severity

Important


Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring Framework
Vendors & Products Vmware
Vmware spring Framework

Tue, 16 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 10:30:00 +0000

Type Values Removed Values Added
Description The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Title CVE-2025-41249: Spring Framework Annotation Detection Vulnerability
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2025-09-16T10:15:34.118Z

Updated: 2025-09-16T19:29:37.532Z

Reserved: 2025-04-16T09:30:25.625Z

Link: CVE-2025-41249

cve-icon Vulnrichment

Updated: 2025-09-16T19:29:34.207Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-16T11:15:30.887

Modified: 2025-09-16T20:15:35.127

Link: CVE-2025-41249

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-16T10:15:34Z

Links: CVE-2025-41249 - Bugzilla