Maven package intelligence

org.springframework.cloud:spring-cloud-gateway-server-webflux Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.springframework.cloud:spring-cloud-gateway-server-webflux, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.springframework.cloud:spring-cloud-gateway-server-webflux
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerability absent from CISA KEV
Sensor Observed
0
org.springframework.cloud:spring-cloud-gateway-server-webflux KEVs with sensor-observed exploitation activity

Review org.springframework.cloud:spring-cloud-gateway-server-webflux exploitation against the versions you run

The single exploited org.springframework.cloud:spring-cloud-gateway-server-webflux vulnerability tracked by Previdian is not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested org.springframework.cloud:spring-cloud-gateway-server-webflux vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2025-41243

Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux

Beyond CISA 06 Oct 2026

Recurring weakness patterns

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this org.springframework.cloud:spring-cloud-gateway-server-webflux KEV portfolio.

Browse all KEVs →