CVE-2026-47879: VMware Spring Cloud Gateway

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier

Affected products

  • VMware Spring Cloud Gateway: before 3.1.14 (fixed in 3.1.14); from 4.0.0, before 4.2.10 (fixed in 4.2.10); from 4.3.0, before 4.3.6 (fixed in 4.3.6); from 5.0.0, before 5.0.3 (fixed in 5.0.3)

Published 2026-08-27. Last modified 2026-09-10.