Time to upgrade! Spring Framework addresses CVE-2025-41242
The fix is available in Spring Framework 6.2.10 (OSS), 5.3.44 (Enterprise), and 6.1.22 (Enterprise).
Tanzu Spring customers can also upgrade to Spring Boot 2.7.28.1, 3.2.17.1, or 3.3.14.1.
spring.io/security/cve...@springio.net