CVE-2025-22235: Spring Boot
High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following conditions are met: * You use Spring Security * EndpointRequest.to() has been used in a Spring Security chain configuration * The endpoint which EndpointRequest references is disabled or not exposed via web * Your application handles requests to /null and this path needs protection You are not affected if any of the following is true: * You don't use Spring Security * You don't use EndpointRequest.to() * The endpoint which EndpointRequest.to() refers to is enabled and is exposed * Your application does not handle requests to /null or this path does not need protection
Affected products
- Spring Spring Boot: from 2.7, before 2.7.25 (fixed in 2.7.25); from 3.1, before 3.1.16 (fixed in 3.1.16); from 3.2, before 3.2.14 (fixed in 3.2.14); from 3.3, before 3.3.11 (fixed in 3.3.11); from 3.4, before 3.4.5 (fixed in 3.4.5)
Published 2025-04-28. Last modified 2026-06-17.