Known vulnerabilities in Spring Cloud Gateway
Vendor:
VMware, Inc
Software:
Spring Cloud Gateway
Software CPE:
cpe:2.3:a:vmware:spring_cloud_gateway:*:*:*:*:*:*:*:*
Website:
https://www.vmware.com
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.0.2
4.3.5
4.3.4
5.0.1
4.3.3
4.2.7
5.0.0
5.0.0-RC1
5.0.0-M4
4.3.2
4.2.6
4.1.12
3.1.12
5.0.0-M3
5.0.0-M2
3.1.11
4.1.11
4.3.1
4.2.5
4.1.10
5.0.0-M1
4.2.4
4.1.9
2.2.10
4.0.12
4.0.11
4.0.10
4.3.0-RC1
4.3.0-M3
4.3.0-M2
4.3.0-M1
4.3.0
4.2.3
4.2.2
4.2.1
4.2.0-RC1
4.2.0-M2
4.2.0-M1
4.2.0
4.1.8
4.1.7
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0-RC1
4.1.0-M2
4.1.0-M1
4.1.0
4.0.9
4.0.8
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0-RC3
4.0.0-RC2
4.0.0-RC1
4.0.0-M5
4.0.0-M4
4.0.0-M3
4.0.0-M2
4.0.0-M1
4.0.0
3.1.10
3.1.9
3.1.8
3.1.7
3.1.6
3.1.5
3.1.4
3.1.3
3.1.2
3.1.0-RC1
3.1.0-M3
3.1.0-M2
3.1.0-M1
3.0.8
3.0.0.M1
3.0.0-RC1
3.0.0-M6
3.0.0-M5
3.0.0-M4
3.0.0-M3
3.0.0-M2
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0.RC2
2.2.0.RC1
2.2.0.M3
2.2.0.M2
2.2.0.M1
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0.RC3
2.1.0.RC2
2.1.0.RC1
2.1.0.M3
2.1.0.M2
2.1.0.M1
2.1.0
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0.RC2
2.0.0.RC1
2.0.0.M9
2.0.0.M8
2.0.0.M7
2.0.0.M6
2.0.0.M5
2.0.0.M4
2.0.0.M3
2.0.0.M2
2.0.0.M1
2.0.0
1.0.3
1.0.2
1.0.1
1.0.0.RC1
1.0.0.M1
1.0.0
3.0.7
3.1.1
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
3.1.0
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125720 - Configuration CVE-2026-22750 |
CWE-16 | Medium | 4.2.1 | 09.04.2026 |
SB2026040995 |
||
| #VU117304 - Exposure of sensitive information to an unauthorized actor CVE-2025-41253 |
CWE-200 | Medium | 3.1.12, 4.1.12, 4.2.6, 4.3.2 | 16.10.2025 |
SB2025101623 SB2025121921 SB2026042275 and 2 more |
||
| #VU114995 - Improper Control of Generation of Code ('Code Injection') CVE-2025-41243 |
CWE-94 | High | 3.1.11, 4.1.11, 4.2.5, 4.3.1 | 09.09.2025 |
SB2025090910 |
||
| #VU109961 - Insufficient Verification of Data Authenticity CVE-2025-41235 |
CWE-345 | Medium | 3.1.10, 4.0.12, 4.1.8, 4.2.3, 4.3.0 | 30.05.2025 |
SB2025053004 SB2025082716 SB2025100115 and 2 more |
||
| #VU60983 - Security Features CVE-2022-22946 |
CWE-254 | Low | 3.1.1 | 03.03.2022 |
SB2022030313 |
||
| #VU60982 - Improper Control of Generation of Code ('Code Injection') CVE-2022-22947 |
CWE-94 | High | 3.0.7, 3.1.1 | 03.03.2022 |
SB2022030313 SB2022042263 SB2022042264 and 4 more |