Input Validation Vulnerability in Spring Cloud Gateway Server by VMware
CVE-2026-47825

8.6HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
15 June 2026

What is CVE-2026-47825?

The Spring Cloud Gateway Server, utilized for routing applications, exhibits a vulnerability where it improperly forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in specific configurations. This could lead to potential exposure to spoofed IP addresses, making it possible for attackers to exploit trust relationships in applications that rely on this data. Both the WebMVC and WebFlux Gateway Servers are affected. Users are encouraged to upgrade to the recommended fixed versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Spring Cloud Gateway 3.1.0 < 3.1.13

Spring Cloud Gateway 4.1.0 < 4.1.13

Spring Cloud Gateway 4.2.0 < 4.2.9

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.