StackRadar

CVE-2025-41248

High

Advisory

Published 16 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

Spring Security annotation detection mechanism has authorization bypass

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven6.4.1, 6.4.3, 6.4.4, 6.4.5+3 more6.4.10, 6.5.413
OSV records
GHSA-8v5q-rhf3-jphm

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
spring-security-core@6.4.4
6.4.10

Open the chart page →

4,983
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-security-core@6.4.5
6.4.10

Open the chart page →

6,328
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-security-core@6.4.5
6.4.10

Open the chart page →

6,328
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-security-core@6.4.6
6.4.10

Open the chart page →

4,378
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-security-core@6.4.5
6.4.10

Open the chart page →

1,816
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
spring-security-core@6.4.4
6.4.10

Open the chart page →

4,578
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-security-core@6.4.3
6.4.10

Open the chart page →

1,269
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-core@6.4.4
6.4.10

Open the chart page →

7,792
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-core@6.4.5
6.4.10

Open the chart page →

3,774
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-core@6.5.3
6.5.4

Open the chart page →

1,947
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-security-core@6.4.1
6.4.10

Open the chart page →

3,131
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
spring-security-core@6.4.4
6.4.10

Open the chart page →

1,783
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-core@6.4.4
6.4.10

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-core@6.4.4
6.4.10

Open the chart page →

2,003
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-41248.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-security-core@6.5.2
6.5.4

Open the chart page →

1,689

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
spring-security-core@6.4.4
6.4.10
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-security-core@6.4.5
6.4.10
2
2martens/wahlrecht:latestba2c3040dab0
spring-security-core@6.5.2
6.5.4
1
bluerange/bluerange:26.1.307c8f73b55df
spring-security-core@6.4.5
6.4.10
1
castlemock/castlemock:latestb7f3f1527ba9
spring-security-core@6.4.4
6.4.10
1
gotson/komga:1.22.0ba892ab3e082
spring-security-core@6.4.1
6.4.10
1
nacos/nacos-server:v3.0.20e951a1d07bb
spring-security-core@6.4.4
6.4.10
1
nacos/nacos-server:v3.0.130a39cb0c54d
spring-security-core@6.4.4
6.4.10
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-core@6.4.4
6.4.10
1
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-security-core@6.4.6
6.4.10
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-core@6.4.5
6.4.10
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-core@6.5.3
6.5.4
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-security-core@6.4.3
6.4.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.