SCA: security update for org.springframework.cloud:spring-cloud-gateway-server (GHSA-fwxx-wv44-7qfg)

high Tenable Self-Hosted Container Security Plugin ID 437907

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose
environment variables and system properties to attackers. An application should be considered vulnerable
when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring
Cloud Gateway Server WebMVC is not vulnerable). * An admin or untrusted third party using Spring
Expression Language (SpEL) to access environment variables or system properties via routes. * An untrusted
third party could create a route that uses SpEL to access environment variables or system properties if: *
The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via
management.endpoints.web.exposure.include=gateway and management.endpoint.gateway.enabled=trueor
management.endpoint.gateway.access=unrestricte. * The actuator endpoints are available to attackers. * The
actuator endpoints are unsecured. (CVE-2025-41253)

See Also

https://github.com/advisories/GHSA-fwxx-wv44-7qfg

Plugin Details

Severity: High

ID: 437907

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 2/20/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.69

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2025-41253

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/16/2025

Vulnerability Publication Date: 10/16/2025

Reference Information

CVE: CVE-2025-41253

cwe: CWE-917