PT-2025-21751 · Unknown+1 · Spring Framework+1

Published

2025-05-16

·

Updated

2026-05-18

·

CVE-2025-22233

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Spring Framework versions 5.3.0 through 5.3.42 Spring Framework versions 6.0.0 through 6.0.27 Spring Framework versions 6.1.0 through 6.1.19 Spring Framework versions 6.2.0 through 6.2.6
Description: The issue concerns a bypass of disallowed fields checks in the Spring Framework. This allows for potential exploitation. The estimated number of affected devices is not provided. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the possibility of bypassing the disallowedFields checks. To avoid confusion, no specific API endpoints or vulnerable parameters are mentioned in the provided descriptions.
Recommendations: For Spring Framework versions 5.3.0 through 5.3.42, upgrade to version 5.3.43. For Spring Framework versions 6.0.0 through 6.0.27, upgrade to version 6.0.28. For Spring Framework versions 6.1.0 through 6.1.19, upgrade to version 6.1.20. For Spring Framework versions 6.2.0 through 6.2.6, upgrade to version 6.2.7. As a general mitigation measure, consider using a dedicated model object with properties only for data binding or using constructor binding with the declarativeBinding flag turned off to minimize the risk of exploitation. Prefer the use of allowedFields over disallowedFields for setting binding.

Fix

RCE

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2025-22233
GHSA-4WP7-92PW-Q264

Affected Products

Debian
Spring Framework