CVE-2025-22233: Spring Framework DataBinder Case Sensitive Match Exception

Published May 16, 2025
·
Updated

CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks.

Affected Spring Products and Versions

Spring Framework: 6.2.0 - 6.2.6

6.1.0 - 6.1.19

6.0.0 - 6.0.27

5.3.0 - 5.3.42 Older, unsupported versions are also affected

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.

| Affected version(s) | Fix Version | Availability | | - | - | - | | 6.2.x | 6.2.7 | OSS | | 6.1.x | 6.1.20 | OSS | | 6.0.x | 6.0.28 | Commercial https://enterprise.spring.io/ | | 5.3.x | 5.3.43 | Commercial https://enterprise.spring.io/ |

No further mitigation steps are necessary.

Generally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. See the Model Design section in the reference documentation.

For setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields.

Credit

This issue was responsibly reported by the TERASOLUNA Framework Development Team from NTT DATA Group Corporation.

Other sources

CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks.

Affected Spring Products and Versions

Spring Framework: 6.2.0 - 6.2.6

6.1.0 - 6.1.19

6.0.0 - 6.0.27

5.3.0 - 5.3.42 Older, unsupported versions are also affected

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s)Fix Version Availability 6.2.x 6.2.7 OSS6.1.x 6.1.20 OSS6.0.x 6.0.28 Commercial

IBM

Affected Software

6 affected componentsFixes available
Spring Spring Framework>=6.2.0<=6.2.6, >=6.1.0<=6.1.19, >=6.0.0<=6.0.27, >=5.3.0<=5.3.42
maven/org.springframework:spring-context<=5.3.39
maven/org.springframework:spring-context>=6.0.0<=6.0.23
maven/org.springframework:spring-context>=6.1.0<=6.1.19
6.1.20
maven/org.springframework:spring-context>=6.2.0<=6.2.6
6.2.7
IBM API Connect V12 OnPrem<=All

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.springframework:spring-context to a version that resolves this vulnerability.

    Fixed in 6.1.20
  2. Upgrade

    Upgrade maven/org.springframework:spring-context to a version that resolves this vulnerability.

    Fixed in 6.2.7
  3. Upgrade

    Upgrade Spring Framework to a version that resolves this vulnerability.

    Fixed in 5.3.43
  4. Upgrade

    Upgrade Spring Framework to a version that resolves this vulnerability.

    Fixed in 6.0.28
  5. Upgrade

    Upgrade Spring Framework to a version that resolves this vulnerability.

    Fixed in 6.1.20
  6. Upgrade

    Upgrade Spring Framework to a version that resolves this vulnerability.

    Fixed in 6.2.7
  7. Configuration

    For setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields. Mitigates bypass risk of disallowedFields checks mentioned in the document.

    Spring Framework DataBinder (allowedFields/disallowedFields) disallowedFields = prefer allowedFields
  8. Configuration

    Use constructor binding and turn off setter binding through the declarativeBinding flag (as described: constructor arguments explicitly declare what to bind together with turning off setter binding via declarativeBinding).

    Spring Framework DataBinder declarativeBinding flag = turn off setter binding
  9. Configuration

    Generally, use a dedicated model object with properties only for data binding (as recommended) to reduce the impact of the DataBinder case-sensitive match issue.

    Spring Framework DataBinder use of dedicated model object for data binding = properties only for data binding

Event History

May 16, 2025
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:32 PM
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-22233?

CVE-2025-22233 has a medium severity rating which indicates potential impacts on data integrity.

2

How do I fix CVE-2025-22233?

To fix CVE-2025-22233, it is recommended to upgrade to the latest version of Spring Framework that addresses this vulnerability.

3

What versions of Spring Framework are affected by CVE-2025-22233?

CVE-2025-22233 affects Spring Framework versions from 5.3.0 to 5.3.42, 6.0.0 to 6.0.27, 6.1.0 to 6.1.19, and 6.2.0 to 6.2.6.

4

What is the nature of the vulnerability in CVE-2025-22233?

CVE-2025-22233 allows bypassing of disallowedFields checks, potentially leading to unauthorized data access.

5

Is CVE-2025-22233 a critical vulnerability?

CVE-2025-22233 is not classified as critical but poses risks that should be addressed due to data integrity concerns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203