CVE-2019-11289: Cloudfoundry Cf-Deployment

High severity, CVSS 8.6. EPSS: 1.5% chance of exploitation in the next 30 days.

Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.

Affected products

  • Cloudfoundry Cf-Deployment: before 12.8.0 (fixed in 12.8.0)
  • Cloudfoundry Routing-Release: before 0.193.0 (fixed in 0.193.0)

Published 2019-11-19. Last modified 2026-06-17.