CVE-2026-47825

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
Configurations

No configuration.

History

15 Jun 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-15 21:17

Updated : 2026-06-23 21:17


NVD link : CVE-2026-47825

Mitre link : CVE-2026-47825

CVE.ORG link : CVE-2026-47825


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error