Spring Cloud Gateway是美国Spring公司开源的一款API网关框架。 Spring Cloud Gateway存在输入验证错误漏洞,该漏洞源于在某些配置场景下将X-Forwarded-For和Forwarded报头从不可信代理转发,影响WebMVC和WebFlux Gateway Server。以下版本受到影响:Spring Cloud Gateway 3.1.13之前版本的3.1.x版本、Spring Cloud Gateway 4.1.13之前版本的4.1.x版本、Spring C
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Cloud Gateway | 3.1.0< 3.1.13 |
affected |
4.1.0< 4.1.13 |
affected | ||
4.2.0< 4.2.9 |
affected | ||
4.3.0< 4.3.4.1 |
affected | ||
5.0.0< 5.0.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Cloud Gateway | 3.1.0 ~ 3.1.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47835 | 8.6 HIGH | Spring AI vector store metadata filtering to handle special characters in Elasticsearch, O |
| CVE-2026-41708 | 7.5 HIGH | Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability |
No comments yet