Spring Security 6.4.0 - 6.4.3 may not correctly locate method...
Vulnerability Description
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-22223
Credits & Attribution
No credits recorded in the NVD database.
References
More from Spring
View All →Affected Vendor
Spring
View all reports →