VDB
Sign up
HIGH7.5

GHSA-8v5q-rhf3-jphm

Spring Security annotation detection mechanism has authorization bypass

Quick fix

GHSA-8v5q-rhf3-jphm — org.springframework.security:spring-security-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>6.4.10</version> for org.springframework.security:spring-security-core

Details

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.

Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.

You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.

This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.security:spring-security-core
Introduced in: 6.4.0Fixed in: 6.4.10
Fix# pom.xml: bump <version>6.4.10</version> for org.springframework.security:spring-security-core
Maven/org.springframework.security:spring-security-core
Introduced in: 6.5.0Fixed in: 6.5.4
Fix# pom.xml: bump <version>6.5.4</version> for org.springframework.security:spring-security-core

References