StackRadar

CVE-2025-41234

Medium

Advisory

Published 13 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework vulnerable to a reflected file download (RFD)

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
spring-webmaven6.0.7, 6.0.9, 6.0.10, 6.0.11+22 more6.1.21, 6.2.863
OSV records
GHSA-6r3c-xf4w-jxjm

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-web@6.0.9
no fix listed

Open the chart page →

3,083
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
spring-web@6.1.10
6.1.21

Open the chart page →

2,141
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
spring-web@6.2.5
6.2.8

Open the chart page →

1,783
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-web@6.2.5
6.2.8

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-web@6.2.5
6.2.8

Open the chart page →

2,003
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-web@6.0.11
no fix listed

Open the chart page →

1,597
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
spring-web@6.1.19
6.1.21

Open the chart page →

4,674
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-web@6.0.13
no fix listed

Open the chart page →

3,221
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
spring-web@6.1.12
6.1.21

Open the chart page →

2,144
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-web@6.1.12
6.1.21

Open the chart page →

2,634
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-web@6.1.1
6.1.21

Open the chart page →

11,577
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-41234.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
spring-web@6.0.10
no fix listed

Open the chart page →

3,480

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-web@6.0.11
no fix listed
3
apache/fineract:1.12.1a83cf1980609
spring-web@6.2.5
6.2.8
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-web@6.2.6
6.2.8
2
dina1993/airports-api:latestac731244aed1
spring-web@6.0.7
no fix listed
2
dina1993/airports-consumer:latest669d146a5e63
spring-web@6.0.7
no fix listed
2
dina1993/airports-producer:latest3d6b0dac1cb4
spring-web@6.0.7
no fix listed
2
hazelcast/management-center:5.5.2991ddb27c251
spring-web@6.1.12
6.1.21
2
2martens/configserver:latestbf1cdb80239d
spring-web@6.1.12
6.1.21
1
adityaprasadpathak/myapp:3.07e3b9777362c
spring-web@6.1.10
6.1.21
1
apache/hertzbeat:1.8.075d48a62748f
spring-web@6.2.2
6.2.8
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
spring-web@6.2.2
6.2.8
1
bluerange/bluerange:26.1.307c8f73b55df
spring-web@6.2.6
6.2.8
1
camunda/zeebe:8.4.5ab5abc09e407
spring-web@6.1.4
6.1.21
1
castlemock/castlemock:latestb7f3f1527ba9
spring-web@6.2.5
6.2.8
1
conductoross/conductor:3.31.09fba127693e6
spring-web@6.1.19
6.1.21
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
spring-web@6.1.5
6.1.21
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
spring-web@6.1.4
6.1.21
1
fabioformosa/hello-world-api:latest063873af085c
spring-web@6.2.5
6.2.8
1
flowable/flowable-rest:7.1.0b7ae287502cd
spring-web@6.1.13
6.1.21
1
folioci/mod-ldp:latestb55696fd9065
spring-web@6.1.5
6.1.21
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-web@6.0.13
no fix listed
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
spring-web@6.1.14
6.1.21
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
spring-web@6.1.14
6.1.21
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
spring-web@6.1.14
6.1.21
1
gotson/komga:1.22.0ba892ab3e082
spring-web@6.2.0
6.2.8
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
spring-web@6.0.11
no fix listed
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
spring-web@6.1.4
6.1.21
1
kubebb/mesh-api:v5.7.0a3879931dfa1
spring-web@6.0.11
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
spring-web@6.1.8
6.1.21
1
lavandadelpatio/tmdb:latestded9377636e9
spring-web@6.0.13
no fix listed
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-web@6.0.7
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-web@6.1.12
6.1.21
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-web@6.0.12
no fix listed
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-web@6.0.12
no fix listed
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
spring-web@6.0.12
no fix listed
1
nacos/nacos-server:v3.0.20e951a1d07bb
spring-web@6.2.5
6.2.8
1
nacos/nacos-server:v3.0.130a39cb0c54d
spring-web@6.2.5
6.2.8
1
openbas/platform:2.0.5d986d80b0a75
spring-web@6.1.16
6.1.21
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-web@6.2.5
6.2.8
1
rabeh/apibootspring:1.0941007b6946e
spring-web@6.1.1
6.1.21
1
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-web@6.2.7
6.2.8
1
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-web@6.2.1
6.2.8
1
treskon/portrait:DEV-latest88e813f22347
spring-web@6.1.15
6.1.21
1
vincentgwzhang/k8sforjava:latesta9139f2cd98f
spring-web@6.2.1
6.2.8
1
vitalii1992/account-service:latest0e694d94551d
spring-web@6.0.9
no fix listed
1
vitalii1992/analytics-service:latest8e798836ecea
spring-web@6.0.9
no fix listed
1
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-web@6.0.9
no fix listed
1
vitalii1992/order-service:latest07c4a8833ce4
spring-web@6.0.9
no fix listed
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-web@6.0.9
no fix listed
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
spring-web@6.0.10
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.