CVE-2019-11289: Cloudfoundry Cf-Deployment
High severity, CVSS 8.6. EPSS: 1.5% chance of exploitation in the next 30 days.
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
Affected products
- Cloudfoundry Cf-Deployment: before 12.8.0 (fixed in 12.8.0)
- Cloudfoundry Routing-Release: before 0.193.0 (fixed in 0.193.0)
Published 2019-11-19. Last modified 2026-06-17.