Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-41248

Spring Security: method security annotations in generic type hierarchies may not be found

Technology

Spring Security

CVSS Score

7.5 / 10.0

Affected Versions

6.4.0 to 6.4.10; 6.5.0 to 6.5.4

Upstream Fix

6.4.11; 6.5.5

Published

September 16, 2025

OSSeva Coverage

Fixed upstream

Description

Spring Security's annotation detection may not resolve annotations on methods in type hierarchies with a parameterized supertype that uses unbounded generics, so @PreAuthorize and other method security annotations can be bypassed. Only applications using @EnableMethodSecurity with annotations on methods in generic superclasses or interfaces are affected. It was published with the Spring Framework CVE-2025-41249. The 7.5 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 6.4.0 to 6.4.10; 6.5.0 to 6.5.4, you need this patch. Book a discovery call to get covered.