CVE-2025-41253High· 7.5▾ TwilightThe following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers.
An application should be considered vulnerable when all the following are true:
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-40477Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-104711Critical· 9.8Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts
CVE-2021-45046Critical· 9.0Incomplete fix for Apache Log4j vulnerability
CVE-2026-87830Critical· 9.1In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path
CVE-2026-57281High· 7.5Jenkins Script Security Plugin has a script security bypass vulnerability