Improper access control in Spring Cloud Gateway - CVE-2026-47879

 

Improper access control in Spring Cloud Gateway - CVE-2026-47879

Published: August 28, 2026


Vulnerability identifier: #VU146233
CSH Severity: Low
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47879
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access native files and perform server-side request forgery.

The vulnerability exists due to improper access control in JsonToGrpcGatewayFilterFactory when processing proto descriptor resource locations. A remote privileged user can specify an arbitrary Spring Resource location to access native files and perform server-side request forgery.


Affected software

Spring Cloud Gateway

How to mitigate CVE-2026-47879

Install security update from vendor's website.

Spring Cloud Gateway - addressed in versions 3.1.14, 4.2.10, 4.3.6, 5.0.3

External References

Related Security Bulletins