Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Oct 16, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 17, 2025 
      
  
Package
Affected versions
>= 6.2.0, < 6.2.12
      >= 6.1.0, <= 6.1.21
      >= 6.0.0, <= 6.0.23
      <= 5.3.39
  Patched versions
6.2.12
  Description
        Published by the National Vulnerability Database
      Oct 16, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 16, 2025 
    
  
        Reviewed
      Oct 17, 2025 
    
  
        Last updated
      Oct 17, 2025 
    
  
STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.
Affected Spring Products and Versions
Spring Framework:
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
Affected version(s)
No further mitigation steps are necessary.
CreditThis vulnerability was discovered and responsibly reported by Jannis Kaiser.
References