Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
High severity
GitHub Reviewed
Published
Oct 16, 2025
to the GitHub Advisory Database
•
Updated Oct 16, 2025
Package
Affected versions
>= 3.1.0, <= 4.3.0
Patched versions
None
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Reviewed
Oct 16, 2025
Last updated
Oct 16, 2025
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers.
An application should be considered vulnerable when all the following are true:
References