Null Endpoint Exposure Vulnerability in Spring Security Framework
CVE-2025-22235
What is CVE-2025-22235?
The vulnerability occurs in the Spring Security framework when the EndpointRequest.to() method creates a matcher for a null endpoint. This scenario arises if the corresponding actuator endpoint is disabled or not exposed. Applications utilizing Spring Security and handling requests directed to /null without appropriate endpoint exposure may be at risk. To ensure security, developers should verify that their configurations align with best practices and ensure that endpoints are securely managed and monitored.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Boot 2.7.x < 2.7.25
Spring Boot 3.1.x < 3.1.16
Spring Boot 3.2.x < 3.2.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
