High severity8.6NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026
CVE-2026-47825
CVE-2026-47825
Description
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers.
Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=3.1, <3.1.13 || >=4.1, <4.1.13 || >=4.2, <4.2.9 || >=4.3, <4.3.5 || >=5.0, <5.0.2
Patches
Vulnerability mechanics
References
1News mentions
1- Spring Projects: Three High-Severity CVEs Disclosed Across Cloud Gateway, AI Vector Stores, and SleuthVypr Intelligence · Jun 15, 2026