CVE-2025-22233: Spring Framework DataBinder Case Sensitive Match Exception

Published May 16, 2025
·
Updated

CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Spring Framework: * 6.2.0 - 6.2.6 * 6.1.0 - 6.1.19 * 6.0.0 - 6.0.27 * 5.3.0 - 5.3.42 * Older, unsupported versions are also affected Mitigation Users of affected versions should upgrade to the corresponding fixed version. | Affected version(s) | Fix Version | Availability | | - | - | - | | 6.2.x | 6.2.7 | OSS | | 6.1.x | 6.1.20 | OSS | | 6.0.x | 6.0.28 | Commercial https://enterprise.spring.io/ | | 5.3.x | 5.3.43 | Commercial https://enterprise.spring.io/ | No further mitigation steps are necessary. Generally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. See the Model Design section in the reference documentation. For setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields. Credit This issue was responsibly reported by the TERASOLUNA Framework Development Team from NTT DATA Group Corporation.

Affected Software

7 affected componentsFixes available
Spring Spring Framework>=6.2.0<=6.2.6, >=6.1.0<=6.1.19, >=6.0.0<=6.0.27, >=5.3.0<=5.3.42
maven/org.springframework:spring-context<=5.3.39
maven/org.springframework:spring-context>=6.0.0<=6.0.23
maven/org.springframework:spring-context>=6.1.0<=6.1.19
6.1.20
maven/org.springframework:spring-context>=6.2.0<=6.2.6
6.2.7
IBM Planning Analytics Local - IBM Planning Analytics Workspace<=2.1.0 - 2.1.13
IBM Planning Analytics Local - IBM Planning Analytics Workspace<=2.0.0 - 2.0.106

Event History

May 16, 2025
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:32 PM
Sep 30, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-22233?

CVE-2025-22233 has a medium severity rating which indicates potential impacts on data integrity.

2

How do I fix CVE-2025-22233?

To fix CVE-2025-22233, it is recommended to upgrade to the latest version of Spring Framework that addresses this vulnerability.

3

What versions of Spring Framework are affected by CVE-2025-22233?

CVE-2025-22233 affects Spring Framework versions from 5.3.0 to 5.3.42, 6.0.0 to 6.0.27, 6.1.0 to 6.1.19, and 6.2.0 to 6.2.6.

4

What is the nature of the vulnerability in CVE-2025-22233?

CVE-2025-22233 allows bypassing of disallowedFields checks, potentially leading to unauthorized data access.

5

Is CVE-2025-22233 a critical vulnerability?

CVE-2025-22233 is not classified as critical but poses risks that should be addressed due to data integrity concerns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2025-22233 - Spring Framework DataBinder Case Sensitive Match Exception - SecAlerts