Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
References
History

Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
Title Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-06-15T19:34:29.601Z

Reserved: 2026-05-20T10:00:48.930Z

Link: CVE-2026-47825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-15T21:17:13.650

Modified: 2026-06-15T21:17:13.650

Link: CVE-2026-47825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.