CVE-2025-41234: RFD Attack via “Content-Disposition” Header Sourced from Request

Published Jun 12, 2025
·
Updated

Description

In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.

Specifically, an application is vulnerable when all the following are true:

- The header is prepared with org.springframework.http.ContentDisposition. - The filename is set via ContentDisposition.Builder#filename(String, Charset). - The value for the filename is derived from user-supplied input. - The application does not sanitize the user-supplied input. - The downloaded content of the response is injected with malicious commands by the attacker (see RFD paper reference for details).

An application is not vulnerable if any of the following is true:

- The application does not set a “Content-Disposition” response header. - The header is not prepared with org.springframework.http.ContentDisposition. - The filename is set via one of: - ContentDisposition.Builder#filename(String), or - ContentDisposition.Builder#filename(String, ASCII) - The filename is not derived from user-supplied input. - The filename is derived from user-supplied input but sanitized by the application. - The attacker cannot inject malicious content in the downloaded content of the response.

Affected Spring Products and VersionsSpring Framework

- 6.2.0 - 6.2.7 - 6.1.0 - 6.1.20 - 6.0.5 - 6.0.28 - Older, unsupported versions are not affected

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.

| Affected version(s) | Fix version | Availability | | - | - | - | | 6.2.x | 6.2.8 | OSS | | 6.1.x | 6.1.21 | OSS | | 6.0.x | 6.0.29 | Commercial |

No further mitigation steps are necessary.

Other sources

Description

In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.

Specifically, an application is vulnerable when all the following are true:

The header is prepared with org.springframework.http.ContentDisposition. The filename is set via ContentDisposition.Builder#filename(String, Charset). The value for the filename is derived from user-supplied input. The application does not sanitize the user-supplied input. The downloaded content of the response is injected with malicious commands by the attacker (see RFD paper reference for details).

An application is not vulnerable if any of the following is true:

The application does not set a “Content-Disposition” response header. The header is not prepared with org.springframework.http.ContentDisposition. The filename is set via one of: ContentDisposition.Builder#filename(String), or ContentDisposition.Builder#filename(String, ASCII)

The filename is not derived from user-supplied input. The filename is derived from user-supplied input but sanitized by the application. The attacker cannot inject malicious content in the downloaded content of the response.

Affected Spring Products and VersionsSpring Framework:

6.2.0 - 6.2.7 6.1.0 - 6.1.20 6.0.5 - 6.0.28 Older, unsupported versions are not affected

MitigationUsers of affected versions should upgrade to the corresponding fixed version.

Affected version(s)Fix versionAvailability6.2.x6.2.8OSS6.1.x6.1.21OSS6.0.x6.0.29 Commercial

IBM

Affected Software

3 affected componentsFixes available
maven/org.springframework:spring-web>=6.0.5<=6.0.23
maven/org.springframework:spring-web>=6.1.0<6.1.21
6.1.21
maven/org.springframework:spring-web>=6.2.0<6.2.8
6.2.8

Event History

Jun 12, 2025
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Jun 13, 2025
Advisory Published
via GitHub·12:33 AM
Data Sourced
via GitHub·12:33 AM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-41234?

CVE-2025-41234 has a CVSS score that indicates it is a serious vulnerability due to the potential for reflected file download attacks.

2

How do I fix CVE-2025-41234?

To fix CVE-2025-41234, update your Spring Framework version to 6.0.23, 6.1.21, or 6.2.8 or later.

3

What does CVE-2025-41234 impact?

CVE-2025-41234 impacts applications using affected versions of the Spring Framework's spring-web module.

4

Is CVE-2025-41234 an exploitable vulnerability?

Yes, CVE-2025-41234 is exploitable as it allows attackers to craft malicious downloads due to improper handling of the Content-Disposition header.

5

What types of attacks are possible with CVE-2025-41234?

CVE-2025-41234 can lead to reflected file download (RFD) attacks, allowing attackers to trick users into downloading harmful files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203