Maven package intelligence
org.springframework.cloud:spring-cloud-gateway-server-webflux Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Maven package org.springframework.cloud:spring-cloud-gateway-server-webflux, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 1
- Known exploited vulnerability affecting org.springframework.cloud:spring-cloud-gateway-server-webflux
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited vulnerability absent from CISA KEV
- Sensor Observed
- 0
- org.springframework.cloud:spring-cloud-gateway-server-webflux KEVs with sensor-observed exploitation activity
Review org.springframework.cloud:spring-cloud-gateway-server-webflux exploitation against the versions you run
The single exploited org.springframework.cloud:spring-cloud-gateway-server-webflux vulnerability tracked by Previdian is not in CISA KEV.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
Attested org.springframework.cloud:spring-cloud-gateway-server-webflux vulnerabilities
1 known exploited vulnerability affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2025-41243
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux |
Beyond CISA | 06 Oct 2026 |
Recurring weakness patterns
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this org.springframework.cloud:spring-cloud-gateway-server-webflux KEV portfolio.