CVE-2025-41235
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
Description
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
Base CVSS
8.6
EPSS Score
0.06%
Introduced Version
2.0.0.RELEASE
Fix Available
4.1.8,4.2.3,3.1.10
Available Patches
Package
CVEs Fixed
Lines of Code Changed