GHSA-fwxx-wv44-7qfg
Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
CVEs:GHSA-fwxx-wv44-7qfg
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
CVEs:GHSA-fwxx-wv44-7qfg
Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
CVEs:CVE-2025-41253
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVEs:GHSA-7fch-4f2f-jcgm
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVEs:CVE-2025-41254
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.