Vulnerability Intelligence Report
CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods
CVE-2025-41232
Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by this if the following are true: * You are using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and * You have Spring Security method annotations on a private method In that case, the target method may be able to be invoked without proper authorization. You are not affected if: * You are not using @EnableMethodSecurity(mode=ASPECTJ) or spring-security-aspects, or * You have no Spring Security-annotated private methods
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:0.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-693 ↗CWE-693 Protection Mechanism Failure
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Spring | Spring Security | 6.4.x < 6.4.6 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.516%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2025-04-16T09:29:46 |
| Published | 2025-05-21T10:23:07 |
| Patch Date | 2025-05-19 |
| Last Updated | 2026-02-26T18:28:04 |
Community Chatter & Buzz