Reflected File Download Vulnerability in Spring Framework by VMware
CVE-2025-41234
What is CVE-2025-41234?
A vulnerability in VMware's Spring Framework affects versions 6.0.5 to 6.2.7, enabling attackers to exploit reflected file download (RFD) attacks. This occurs when an application improperly handles the 'Content-Disposition' header by using non-ASCII charsets for filenames derived from user input without proper sanitization. Attackers can inject malicious commands into the response content, potentially compromising application security. To mitigate this risk, users should promptly upgrade to the fixed versions available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Framework 6.0.5 <= 6.0.28
Spring Framework 6.1.0 <= 6.1.20
Spring Framework 6.2.0 <= 6.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved