CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods

Published May 21, 2025
·
Updated

Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass.

Your application may be affected by this if the following are true:

You are using @EnableMethodSecurity(mode=ASPECTJ) and spring-security-aspects, and You have Spring Security method annotations on a private method In that case, the target method may be able to be invoked without proper authorization.

You are not affected if:

You are not using @EnableMethodSecurity(mode=ASPECTJ) or spring-security-aspects, or You have no Spring Security-annotated private methods

Affected Software

2 affected componentsFixes available
VMware Spring Security
maven/org.springframework.security:spring-security-aspects>=6.4.0<6.4.6
6.4.6

Event History

May 21, 2025
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:30 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-41232?

CVE-2025-41232 is classified as a high severity vulnerability due to the potential for authorization bypass.

2

How do I fix CVE-2025-41232?

To fix CVE-2025-41232, ensure that method security annotations are correctly applied to methods and consider adjusting your configuration to avoid private method access issues.

3

What impact does CVE-2025-41232 have on my application?

CVE-2025-41232 could lead to unauthorized access as the security aspects may fail to enforce method security on private methods.

4

Which versions of Spring Security are affected by CVE-2025-41232?

CVE-2025-41232 affects VMware Spring Security configurations that utilize @EnableMethodSecurity(mode=ASPECTJ) for method authorization.

5

Is CVE-2025-41232 actively being exploited?

As of now, there have been no reported active exploits for CVE-2025-41232, but it is advisable to apply mitigations as a precaution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203