Status: UPDATED | Advisory ID: CVE-2026-47825
| CVE | CVE-2026-47825 |
| CVSS Score / Version | 8.6 (High) / CVSS v3.1 |
| Updated | 2026-10-01 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is high; availability impact is none. |
| Affected products | VMware spring_cloud_gateway and Spring Spring Cloud Gateway |
| Classified as | CWE-346 (Origin Validation Error) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| VMware | spring_cloud_gateway | ||
| Spring | Spring Cloud Gateway |
| Subsystems | General OT |
| Sectors | Multiple |
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers.
Affected versions:
Spring Cloud Gateway 3.1.x (fix 3.1.13).
Spring Cloud Gateway 4.1.x (fix 4.1.13).
Spring Cloud Gateway 4.2.x (fix 4.2.9).
Spring Cloud Gateway 4.3.x (fix 4.3.5).
Spring Cloud Gateway 5.0.x (fix 5.0.2). (NVD)
Monitor VMware's and Spring's web pages for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-47825 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-47825 |
| Vendor advisory | https://spring.io/security/cve-2026-47825 |