CVE-2018-1221: Cloudfoundry Cf-Deployment

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.

Affected products

  • Cloudfoundry Cf-Deployment: before 1.14.0 (fixed in 1.14.0)
  • Cloudfoundry Routing-Release: before 0.172.0 (fixed in 0.172.0)

Published 2018-03-19. Last modified 2026-06-17.