CVE-2016-8218: Cloudfoundry Cf-Release

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

Affected products

  • Cloudfoundry Cf-Release: up to and including 203; version 204 only; version 205 only; version 206 only; version 207 only; version 208 only; …
  • Cloudfoundry Routing-Release: up to and including 0.141.0

Published 2017-06-13. Last modified 2026-06-17.