← Volver al buscador de CVEs

CVE-2026-47825

Spring Cloud Gateway

Descripción

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).

CVSS 8.6EPSS 0.13899999999999998%Riesgo 0.87
Ver fuente
Publicación
2026-06-15 21:17:13
Versiones afectadas
< 3.1.13, < 4.1.13, < 4.2.9, < 4.3.5, < 5.0.2
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N