CVE-2025-41248
Spring Security: method security annotations in generic type hierarchies may not be found
Technology
Spring Security
CVSS Score
7.5 / 10.0
Affected Versions
6.4.0 to 6.4.10; 6.5.0 to 6.5.4
Upstream Fix
6.4.11; 6.5.5
Published
September 16, 2025
OSSeva Coverage
Fixed upstream
Description
Spring Security's annotation detection may not resolve annotations on methods in type hierarchies with a parameterized supertype that uses unbounded generics, so @PreAuthorize and other method security annotations can be bypassed. Only applications using @EnableMethodSecurity with annotations on methods in generic superclasses or interfaces are affected. It was published with the Spring Framework CVE-2025-41249. The 7.5 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 6.4.0 to 6.4.10; 6.5.0 to 6.5.4, you need this patch. Book a discovery call to get covered.