CVE-2025-41242 is a path traversal vulnerability in Spring Framework MVC applications that serve static resources through Spring MVC resource handling. It arises when such an application is deployed as a WAR or with an embedded Servlet container whose URI canonicalization does not reject suspicious path sequences. Under those conditions, crafted request paths can bypass expected resource-path restrictions. Apache Tomcat and Eclipse Jetty deployments are not affected when their default security protections remain enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small research bundle centered on CVE-2025-41242, a Spring Framework path traversal vulnerability triggered by URI parsing inconsistencies with embedded Jetty. The repo contains three main components: (1) `vulhub/spring/CVE-2025-41242/poc.py`, the actual exploit PoC; (2) Vulhub environment files and documentation for reproducing the issue in Docker; and (3) `GBitsTools/GBitsTools.py`, a helper payload generator that can build ghost-bits style obfuscated strings for several vulnerability presets, including this Spring traversal case. The main exploit capability is arbitrary file read over HTTP/HTTPS. The PoC does not execute commands or drop a shell; it constructs a raw HTTP GET request using repeated UTF-8 bytes for the Chinese string `阮严灵丰丰甲来`, which the vulnerable server-side decoding path collapses into `.%u002e`, ultimately becoming `../` inside Jetty path resolution. The script deliberately avoids standard HTTP client normalization by using raw sockets, because browsers, curl, and many proxies would percent-encode the Unicode path and break exploitation. It also automatically percent-encodes the last byte of the requested filename because the vulnerable Spring decoder path is only reached when at least one byte in the target filename is encoded. Repository structure indicates this is not a framework module like Metasploit or Nuclei. It is a standalone PoC plus lab environment. `vulhub/spring/CVE-2025-41242/docker-compose.yml` exposes port 8080 for the vulnerable Spring Boot 3.2.4 + Jetty service and port 5005 in the lab. The README files provide detailed vulnerability background, affected version ranges, reproduction constraints, and example commands. `GBitsTools.py` offers both CLI and Tkinter GUI modes to generate ghost-bits payloads and includes presets for Spring traversal, Fastjson bypass, Openfire bypass, and SMTP smuggling, but it is a payload-construction utility rather than the exploit itself. Overall, this is a legitimate operational PoC for remote web exploitation of CVE-2025-41242 in a controlled lab setting, focused on reliable arbitrary file disclosure against vulnerable Spring-on-Jetty deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.