CVE-2026-47825: Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers.
Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spring Cloud Gatewayto a version that resolves this vulnerability.Fixed in 3.1.13 - Upgrade
Upgrade
Spring Cloud Gatewayto a version that resolves this vulnerability.Fixed in 4.1.13 - Upgrade
Upgrade
Spring Cloud Gatewayto a version that resolves this vulnerability.Fixed in 4.2.9 - Upgrade
Upgrade
Spring Cloud Gatewayto a version that resolves this vulnerability.Fixed in 4.3.5 - Upgrade
Upgrade
Spring Cloud Gatewayto a version that resolves this vulnerability.Fixed in 5.0.2
Event History
Frequently Asked Questions
Which Spring Cloud Gateway server implementations should be assessed?
Both WebMVC Gateway Server and WebFlux Gateway Server deployments are affected in certain configuration scenarios.
Which releases contain fixes for the affected version lines?
Upgrade to 3.1.13 for 3.1.x, 4.1.13 for 4.1.x, 4.2.9 for 4.2.x, 4.3.5 for 4.3.x, or 5.0.2 for 5.0.x.