SB2026040995 - Information disclosure in Spring Cloud Gateway



SB2026040995 - Information disclosure in Spring Cloud Gateway

Published: April 9, 2026

Security Bulletin ID SB2026040995
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Configuration (CVE-ID: CVE-2026-22750)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper security configuration in SSL bundle configuration handling when processing the spring.ssl.bundle configuration property. A remote attacker can exploit the use of the default SSL configuration to disclose sensitive information.

The configured SSL bundle is silently ignored and the default SSL configuration is used instead.


Remediation

Install update from vendor's website.