PT-2026-49468 · Spring · Spring Cloud Gateway
CVE-2026-47825
·
Published
2026-06-15
·
Updated
2026-06-23
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Cloud Gateway versions prior to 3.1.13
Spring Cloud Gateway versions prior to 4.1.13
Spring Cloud Gateway versions prior to 4.2.9
Spring Cloud Gateway versions prior to 4.3.5
Spring Cloud Gateway versions prior to 5.0.2
Description
Spring Cloud Gateway Server, affecting both WebMVC and WebFlux Gateway Servers, forwards the
X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios.Recommendations
Update to version 3.1.13 or later.
Update to version 4.1.13 or later.
Update to version 4.2.9 or later.
Update to version 4.3.5 or later.
Update to version 5.0.2 or later.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Cloud Gateway