CVE-2026-47825 — CVSS 8.6 (high): Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios…
CVE-2026-47879 — CVSS 7.7 (high): Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring…
CVE-2026-22750 — CVSS 7.5 (high): When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently…
CVE-2021-22051 — CVSS 6.5 (medium): Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream…
CVE-2022-22946 — CVSS 5.5 (medium): In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted…