CVE-2026-7366: IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
Other sources
IBM DataPower Gateway allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataPower Gateway 11.0.0to a version that resolves this vulnerability.Fixed in 11.0.0.2Patch DT469107 - Upgrade
Upgrade
IBM DataPower Gateway 10.5.0to a version that resolves this vulnerability.Fixed in 10.5.0.22Patch DT469107 - Upgrade
Upgrade
IBM DataPower Gateway 10.6.0to a version that resolves this vulnerability.Fixed in 10.6.0.10Patch DT469107
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7366?
The severity of CVE-2026-7366 is medium, with a score of 4.2.
How do I fix CVE-2026-7366?
To mitigate CVE-2026-7366, update your IBM DataPower Gateway to a version that addresses the race condition vulnerability.
What type of vulnerability is CVE-2026-7366?
CVE-2026-7366 is classified as a race condition vulnerability affecting request state isolation.
Which versions of IBM DataPower Gateway are affected by CVE-2026-7366?
CVE-2026-7366 affects IBM DataPower Gateway versions 11.0.0.0 through 11.0.0.1, 10.5.0.0 through 10.5.0.21, and 10.6.0.0 through 10.6.0.9.
What impact does CVE-2026-7366 have on users?
CVE-2026-7366 can lead to improper isolation of request states, potentially resulting in information leakage.