PT-2026-82398 · Vmware · Spring Cloud Gateway

·

CVE-2026-47879

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Cloud Gateway versions 5.0.0 through 5.0.2 Spring Cloud Gateway versions 4.3.0 through 4.3.5 Spring Cloud Gateway versions 4.0.0 through 4.2.9 Spring Cloud Gateway versions 3.1.13 and earlier
Description The JsonToGrpcGatewayFilterFactory allows the use of arbitrary Spring Resource locations when defining the proto descriptor. A proto descriptor is a file that describes the structure of the data and the services provided by a gRPC server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47879

Affected Products

Spring Cloud Gateway