CVE-2026-47825
🟡 Monitoruj
Przekazywanie nagłówków z niezaufanych proxy w Spring Cloud Gateway może prowadzić do ujawnienia danych.
CVSS
8.6
EPSS
0.2%
Exploit
none
Vendor
vmware
Opis źródłowy (NVD)
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-06-15 21:17:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 13:52:27 UTC |
Referencje
- https://spring.io/security/cve-2026-47825 ([email protected]) [Vendor Advisory]