VendorsVMwarespring_cloud_gatewayany version
Vulnerabilities

VMware Spring Cloud Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
Published 2022-03-03 · Analyzed
10.0KEV1 PoCEPSS 0.983
CVE-2026-47879
Spring Cloud Gateway SSRF and native file access with gRPC
Published 2026-08-27 · Analyzed
8.7EPSS 0.003
CVE-2021-22051
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to 2.2.10.RELEASE or newer.
Published 2021-11-08 · Modified
6.5EPSS 0.007