spring-webflux is vulnerable to Protection Mechanism Failure
48
Medium Risk
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Any security-related modifications applied to the ServerRequest by the filter are silently discarded. The downstream handler receives the original, unmodified request instead of the modified one, causing the security enrichment to have no effect.
You are affected if you are using a version that falls within the vulnerable range and if the application uses the Kotlin Router DSL with a filter that passes a modified or replaced ServerRequest (for example, via ServerRequestWrapper) to the next handler function in order to apply security-related concerns.
spring-webflux is vulnerable to Protection Mechanism Failure in versions 5.3.0 - 5.3.48.
Upgrade the org.springframework:spring-webflux library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant