CVE-2025-41235: VMware Spring Cloud Gateway

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.

Affected products

  • VMware Spring Cloud Gateway
  • VMware Spring Cloud Gateway Server Mvc

Published 2025-05-30. Last modified 2026-06-17.