CVE-2025-41243 | VMware Spring Cloud Gateway Server Webflux up to 3.1.10/4.1.10/4.2.4/4.3.0 Actuator Endpoint expression language injection (EUVD-2025-29611)
A vulnerability, which was classified as very critical, has been found in VMware Spring Cloud Gateway Server Webflux up to 3.1.10/4.1.10/4.2.4/4.3.0. This issue affects some unknown processing of the component Actuator Endpoint. This manipulation causes improper neutralization of special elements used in an expression language statement.
This vulnerability appears as CVE-2025-41243. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.