CVE-2026-47825

🟡 Monitoruj

Przekazywanie nagłówków z niezaufanych proxy w Spring Cloud Gateway może prowadzić do ujawnienia danych.

CVSS
8.6
EPSS
0.2%
Exploit
none
Vendor
vmware
Opis źródłowy (NVD)

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-06-15 21:17:13 UTC
Ostatnia modyfikacja (NVD)2026-10-01 13:52:27 UTC
Referencje