Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
by SFN233 — [github.com/SFN233](https://github.com/SFN233) · 2026-07-06
- Severity
- Critical
- CVE
- CVE-2025-41243
- Category
- web
- Affected product
- Spring Cloud Gateway (spring-cloud-starter-gateway 4.1.0 on spring-boot-starter-parent 3.3.0), with Actuator's gateway endpoint exposed
- Affected versions
- Per source repository's pox.xml (sic, actually a Maven pom.xml): spring-cloud-starter-gateway 4.1.0 with spring-boot-starter-actuator and management.endpoints.web.exposure.include=gateway enabled
- Disclosed
- 2026-07-06
- Patch status
- unpatched
Archive entry
intelseclab/poc-archiveMetadata
| Field | Value |
|---|---|
| Date Added | 2026-07-06 |
| Last Updated | 2026-07-06 |
| Author / Researcher | SFN233 — github.com/SFN233 |
| CVE / Advisory | CVE-2025-41243 |
| Category | web |
| Severity | Critical |
| CVSS Score | 10.0 (per NVD) |
| Status | PoC |
| Tags | spring-cloud-gateway, actuator, spel-injection, rce, java, docker, lab-environment |
| Related | N/A |
Affected Target
| Field | Value |
|---|---|
| Software / System | Spring Cloud Gateway (spring-cloud-starter-gateway 4.1.0 on spring-boot-starter-parent 3.3.0), with Actuator’s gateway endpoint exposed |
| Versions Affected | Per source repository’s pox.xml (sic, actually a Maven pom.xml): spring-cloud-starter-gateway 4.1.0 with spring-boot-starter-actuator and management.endpoints.web.exposure.include=gateway enabled |
| Language / Platform | Java / Spring Boot (declared target); the container actually shipped in this repo runs Python 3 |
| Authentication Required | No — the Actuator gateway endpoints are unauthenticated when exposed with the given application.properties |
| Network Access Required | Yes — reach the exposed Actuator/gateway HTTP endpoint (e.g. /actuator/gateway/routes) |
Summary
CVE-2025-41243 concerns a SpEL (Spring Expression Language) injection vulnerability in Spring Cloud Gateway that leads to remote code execution when the Actuator gateway management endpoint is exposed. The root cause is that Actuator’s gateway routes API allows submitting SpEL-backed route predicates/filters that are evaluated server-side without adequate sandboxing, letting an authenticated-to-the-endpoint (here, unauthenticated-by-config) attacker inject expressions that execute arbitrary code in the context of the JVM. This particular repository, however, is not a working exploit — it is a minimal Docker Compose “lab” scaffold: a pom.xml (checked in as pox.xml) and application.properties describe the intended vulnerable Spring Cloud Gateway configuration, but the actual Dockerfile that gets built does not compile or run that Spring application at all. It installs Python 3 on Alpine and runs an inline Python HTTP server that simply returns a static, hardcoded JSON blob ({"status":"UP","CVE":"2025-41243","routes":["hack_route"]}) on any GET request to port 8080. There is no real Spring Cloud Gateway instance, no Actuator, and no SpEL evaluation happening anywhere in this repo — it is a mock/simulated response, not a reproducible vulnerable target.
Vulnerability Details
Root Cause
The genuine CVE-2025-41243 root cause (per the vulnerability class this repo names) is that Spring Cloud Gateway’s Actuator gateway management endpoint accepts and evaluates SpEL expressions embedded in route configuration (predicates/filters) without sufficient restriction, allowing expression injection that reaches Java reflection/OS command execution primitives. The repository’s own README.md states this plainly (translated from Chinese):
“Spring Cloud Gateway has a SpEL expression injection vulnerability; when the Actuator endpoint is enabled, an attacker can achieve remote code execution (RCE).”
However, this specific repo does not implement or reproduce that mechanism. Its Dockerfile fabricates a fake vulnerable-looking response instead of running real Spring Cloud Gateway/Actuator code:
| |
The pox.xml (Maven POM) and application.properties (management.endpoint.gateway.enabled=true, management.endpoints.web.exposure.include=gateway) describe what a real vulnerable configuration would look like, but they are never actually built or run by the Docker image — there is no build step invoking Maven, and the container’s entrypoint is the mock Python server above.
Attack Vector
As documented in the repo (not independently reproducible against this specific container, since it only serves a static response):
- Deploy the environment with
docker-compose up -d. - Access the exposed Actuator gateway endpoint, e.g.
http://<target-ip>:8080/actuator/gateway/routes(mapped to host port 8081 in the provideddocker-compose.yml). - Submit a malicious SpEL payload via the gateway routes/filters API to trigger expression evaluation and achieve RCE (no working payload or curl example is included in the repo).
Impact
If the underlying CVE-2025-41243 were genuinely reproduced, an unauthenticated attacker reaching the exposed Actuator gateway endpoint could achieve remote code execution on the Spring Cloud Gateway host. In this repo’s actual state, no code execution or SpEL evaluation is achievable — the container only returns a static JSON string.
Environment / Lab Setup
docker-compose.yml maps host port 8081 -> container port 8080.
Container image build: FROM alpine:latest + python3 (NOT a real Spring Boot/Java runtime).
Intended-but-unbuilt vulnerable stack (per pom.xml / application.properties):
- spring-boot-starter-parent 3.3.0
- spring-cloud-starter-gateway 4.1.0
- spring-boot-starter-actuator
- management.endpoint.gateway.enabled=true
- management.endpoints.web.exposure.include=gateway
Actual runtime behavior: static mock JSON response on any GET to :8080.
Proof of Concept
PoC Script
No exploit script or payload is included in this repository. It ships only a
docker-compose.yml,Dockerfile,pox.xml(Maven POM), andapplication.properties. The Dockerfile does not build the described Spring Cloud Gateway application — it builds and runs an unrelated static-response Python mock server. There is nothing here to execute against a real target; use only as a reference for the described vulnerability class.
| |
Detection & Indicators of Compromise
GET /actuator/gateway/routes HTTP/1.1
Host: TARGET:8081
Signs of compromise:
- Exposed
/actuator/gateway/**endpoints reachable without authentication. - Route/filter definitions containing SpEL syntax (
#{...}) submitted via the Actuator gateway API. - Unexpected outbound connections or process spawning from the Spring Cloud Gateway JVM process following an Actuator route update.
Remediation
| Action | Detail |
|---|---|
| Primary fix | No official patch identified at time of mirroring — see references. Disable or restrict access to Actuator’s gateway management endpoints, and upgrade Spring Cloud Gateway to a version with hardened SpEL evaluation once available. |
| Interim mitigation | Do not expose management.endpoints.web.exposure.include=gateway (or *) on internet-facing deployments; place Actuator endpoints behind authentication and network ACLs; disable dynamic route/filter updates via the Actuator API where not required. |
References
Notes
Mirrored from https://github.com/SFN233/CVE-2025-41243-Vulnerability-Lab on 2026-07-06. This repository provides only a Docker Compose “vulnerable environment” scaffold and no actual exploit script or payload. On inspection, the Dockerfile it ships does not even build/run the described Spring Cloud Gateway/Actuator stack — it runs a trivial Python mock server that returns a static JSON string mentioning the CVE. Treat this repo as a description/placeholder of the vulnerability class rather than a reproducible lab or working exploit.