Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
High severity
GitHub Reviewed
Published
Oct 16, 2025
to the GitHub Advisory Database
•
Updated Feb 19, 2026
Package
Affected versions
>= 4.3.0, < 4.3.2
>= 4.2.0, < 4.2.6
>= 4.0.0, <= 4.1.9
<= 3.1.10
Patched versions
4.3.2
4.2.6
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Reviewed
Oct 16, 2025
Last updated
Feb 19, 2026
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers.
An application should be considered vulnerable when all the following are true:
References