CVE-2025-41254: Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
(updated )
STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-41254 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →