CVE-2026-47825 PUBLISHED

Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations

Assigner: vmware
Reserved: 20.05.2026 Published: 15.06.2026 Updated: 16.06.2026

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers.

Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS Score: 8.6

Product Status

Vendor Spring
Product Spring Cloud Gateway
Versions Default: unaffected
  • affected from 3.1.0 to 3.1.13 (excl.)
  • affected from 4.1.0 to 4.1.13 (excl.)
  • affected from 4.2.0 to 4.2.9 (excl.)
  • affected from 4.3.0 to 4.3.5 (excl.)
  • affected from 5.0.0 to 5.0.2 (excl.)

References

Problem Types

  • CWE-346: Origin Validation Error CWE

Impacts

  • Per CVSS v3.1: Integrity HIGH (header spoofing from untrusted proxy sources).