Known vulnerabilities in Spring Cloud Gateway

Software CPE: cpe:2.3:a:vmware:spring_cloud_gateway:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Spring Cloud Gateway Spring Cloud Gateway is affected by 6 known vulnerabilities: 2 high, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125720 - Configuration
CVE-2026-22750
CWE-16 Medium
No
No
4.2.1 09.04.2026 SB2026040995
#VU117304 - Exposure of sensitive information to an unauthorized actor
CVE-2025-41253
CWE-200 Medium
No
No
3.1.12, 4.1.12, 4.2.6, 4.3.2 16.10.2025 SB2025101623
SB2025121921
SB2026042275
and 2 more
#VU114995 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-41243
CWE-94 High
No
No
3.1.11, 4.1.11, 4.2.5, 4.3.1 09.09.2025 SB2025090910
#VU109961 - Insufficient Verification of Data Authenticity
CVE-2025-41235
CWE-345 Medium
No
No
3.1.10, 4.0.12, 4.1.8, 4.2.3, 4.3.0 30.05.2025 SB2025053004
SB2025082716
SB2025100115
and 2 more
#VU60983 - Security Features
CVE-2022-22946
CWE-254 Low
Available
No
3.1.1 03.03.2022 SB2022030313
#VU60982 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22947
CWE-94 High
Available
Exploited
3.0.7, 3.1.1 03.03.2022 SB2022030313
SB2022042263
SB2022042264
and 4 more