A critical security vulnerability (CVE-2025-41248) has been discovered in Spring Security that allows authorization bypass when using method security annotations on parameterized types. This vulnerability could potentially allow unauthorized access to protected methods and resources in Spring-based applications.

1m read timeFrom spring.io
Post cover image
Table of contents
DescriptionAffected Spring Products and VersionsMitigationCreditReferences

Sort: