CVE-2025-41235: VMware Spring Cloud Gateway
High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
Affected products
Published 2025-05-30. Last modified 2026-06-17.