StackRadar

CVE-2025-41234

Medium

Advisory

Published 13 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework vulnerable to a reflected file download (RFD)

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
spring-webmaven6.0.7, 6.0.9, 6.0.10, 6.0.11+22 more6.1.21, 6.2.863
OSV records
GHSA-6r3c-xf4w-jxjm

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-web@6.0.9
no fix listed

Open the chart page →

3,083
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
spring-web@6.1.10
6.1.21

Open the chart page →

2,141
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
spring-web@6.2.5
6.2.8

Open the chart page →

1,783
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-web@6.2.5
6.2.8

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-web@6.2.5
6.2.8

Open the chart page →

2,003
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-web@6.0.11
no fix listed

Open the chart page →

1,597
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
spring-web@6.1.19
6.1.21

Open the chart page →

4,674
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-web@6.0.13
no fix listed

Open the chart page →

3,221
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
spring-web@6.1.12
6.1.21

Open the chart page →

2,144
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-web@6.1.12
6.1.21

Open the chart page →

2,634
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-web@6.1.1
6.1.21

Open the chart page →

11,577
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
spring-web@6.0.10
no fix listed

Open the chart page →

3,480

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-web@6.1.2
6.1.21
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-web@6.0.9
no fix listed
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-web@6.2.6
6.2.8
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-web@6.2.1
6.2.8
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-web@6.2.0
6.2.8
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-web@6.2.0
6.2.8
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-web@6.2.3
6.2.8
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-web@6.1.1
6.1.21
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-web@6.1.1
6.1.21
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
spring-web@6.0.11
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
spring-web@6.1.3
6.1.21
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
spring-web@6.1.3
6.1.21
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
spring-web@6.1.3
6.1.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.