
Ghost Bits is a brilliant research: https://i.blackhat.com/Asia-26/Presentations/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf Now you can reproduce CVE-2025-41242 in Vulhub, Spring/Jetty Path traversal caused by Ghost Bits: https://github.com/vulhub/vulhub/tree/master/spring/CVE-2025-41242 This issue exists in spring-boot-starter-jetty <= 3.2.4 with zero configuration https://t.co/1ko3YU0LN9
Post summary
The post provides a proof‑of‑concept repository for CVE‑2025‑41242, detailing a path traversal flaw in Spring Boot Jetty, but offers no evidence of active exploitation, patches, or debunking.

