StackRadar

CVE-2025-41234

Medium

Advisory

Published 13 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework vulnerable to a reflected file download (RFD)

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
spring-webmaven6.0.7, 6.0.9, 6.0.10, 6.0.11+22 more6.1.21, 6.2.863
OSV records
GHSA-6r3c-xf4w-jxjm

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
spring-web@6.2.5
6.2.8

Open the chart page →

4,983
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-web@6.2.6
6.2.8

Open the chart page →

6,328
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
spring-web@6.2.2
6.2.8
apache/hertzbeat-collector:1.8.0a2bab1be574c
spring-web@6.2.2
6.2.8

Open the chart page →

14,000
flowableflowable-oss7.1.01 of 2See more

flowable flowable-oss 7.1.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
flowable/flowable-rest:7.1.0b7ae287502cd
spring-web@6.1.13
6.1.21

Open the chart page →

2,784
hazelcasthazelcastVerified publisher5.10.21 of 2See more

hazelcast hazelcast 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-web@6.1.12
6.1.21

Open the chart page →

2,634
oesopsmxVerified publisher4.0.324 of 25See more

oes opsmx 4.0.32

4 of the 25 container images this version deploys carry CVE-2025-41234.

Open the chart page →

107,811
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-web@6.2.6
6.2.8

Open the chart page →

6,328
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-web@6.2.7
6.2.8

Open the chart page →

4,378
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
spring-web@6.1.4
6.1.21

Open the chart page →

5,291
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-web@6.0.11
no fix listed

Open the chart page →

15,562
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-web@6.1.1
6.1.21

Open the chart page →

13,610
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
spring-web@6.1.15
6.1.21

Open the chart page →

31,844
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
spring-web@6.0.9
no fix listed

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
spring-web@6.0.9
no fix listed

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-web@6.0.9
no fix listed

Open the chart page →

2,853
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
spring-web@6.0.9
no fix listed

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-web@6.0.9
no fix listed

Open the chart page →

2,205
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-web@6.0.7
no fix listed

Open the chart page →

1,958
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
spring-web@6.0.7
no fix listed

Open the chart page →

1,947
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
spring-web@6.0.7
no fix listed

Open the chart page →

1,947
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-web@6.1.12
6.1.21

Open the chart page →

1,748
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
spring-web@6.1.4
6.1.21
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-web@6.1.2
6.1.21

Open the chart page →

28,131
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
spring-web@6.1.1
6.1.21

Open the chart page →

6,187
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-web@6.0.11
no fix listed

Open the chart page →

14,728
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-web@6.2.6
6.2.8

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-web@6.2.1
6.2.8

Open the chart page →

26,996
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
spring-web@6.2.5
6.2.8

Open the chart page →

4,578
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-web@6.2.3
6.2.8

Open the chart page →

1,269
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
spring-web@6.1.5
6.1.21

Open the chart page →

2,512
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
spring-web@6.1.4
6.1.21

Open the chart page →

3,888
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
spring-web@6.1.14
6.1.21
golenski/fibonacci-task-manager:2.0.03a2b36df247b
spring-web@6.1.14
6.1.21
golenski/fibonacci-worker:2.0.0954caf4aaf6a
spring-web@6.1.14
6.1.21

Open the chart page →

16,927
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-web@6.2.5
6.2.8

Open the chart page →

7,792
mod-ldpfolio-org0.1.331 of 1See more

mod-ldp folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
folioci/mod-ldp:latestb55696fd9065
spring-web@6.1.5
6.1.21

Open the chart page →

1,938
hello-world-apihello-world-api0.0.51 of 1See more

hello-world-api hello-world-api 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
fabioformosa/hello-world-api:latest063873af085c
spring-web@6.2.5
6.2.8

Open the chart page →

1,417
helm-airportshelm-airports0.1.03 of 7See more

helm-airports helm-airports 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-web@6.0.7
no fix listed
dina1993/airports-consumer:latest669d146a5e63
spring-web@6.0.7
no fix listed
dina1993/airports-producer:latest3d6b0dac1cb4
spring-web@6.0.7
no fix listed

Open the chart page →

12,696
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
spring-web@6.1.16
6.1.21

Open the chart page →

25,017
sys-info-web-env-view-serverhuajuan-helm-charts0.1.11 of 2See more

sys-info-web-env-view-server huajuan-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
spring-web@6.0.11
no fix listed

Open the chart page →

1,989
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-web@6.2.6
6.2.8

Open the chart page →

3,774
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-web@6.2.1
6.2.8

Open the chart page →

1,345
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-web@6.2.0
6.2.8

Open the chart page →

6,586
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-web@6.2.0
6.2.8

Open the chart page →

6,568
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
spring-web@6.2.1
6.2.8

Open the chart page →

1,476
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
spring-web@6.0.11
no fix listed

Open the chart page →

6,490
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
spring-web@6.1.8
6.1.21

Open the chart page →

7,802
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-web@6.2.0
6.2.8

Open the chart page →

3,131
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
spring-web@6.0.13
no fix listed

Open the chart page →

2,234
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-web@6.0.7
no fix listed

Open the chart page →

3,290
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-web@6.0.12
no fix listed

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-web@6.0.12
no fix listed

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
spring-web@6.0.12
no fix listed

Open the chart page →

4,599

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-web@6.1.2
6.1.21
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-web@6.0.9
no fix listed
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-web@6.2.6
6.2.8
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-web@6.2.1
6.2.8
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-web@6.2.0
6.2.8
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-web@6.2.0
6.2.8
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-web@6.2.3
6.2.8
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-web@6.1.1
6.1.21
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-web@6.1.1
6.1.21
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
spring-web@6.0.11
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
spring-web@6.1.3
6.1.21
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
spring-web@6.1.3
6.1.21
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
spring-web@6.1.3
6.1.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.