spring.io CVE-2026-22750: SSL Configuration Error in Spring Cloud Gateway
Article Content
- •CVE-2026-22750 affects SSL configuration in Spring Cloud Gateway.
- •The vulnerability allows default SSL settings to be used instead of custom configurations.
- •A patch is available for enterprise users; others should upgrade to versions 5.0.2 or 5.1.1.
A vulnerability (CVE-2026-22750) was identified in VMware Tanzu Spring Cloud Gateway, where SSL configurations using the property spring.ssl.bundle were ignored, leading to the use of default SSL settings. This issue affects users of Spring Cloud Gateway 4.2.0 and earlier versions, potentially compromising security if administrators make critical changes that are not applied. The vulnerability was reported by Otmane Omry and has been classified as 'high' severity. A patch has been released in version 4.2.1, but it is only available to enterprise customers. Users are advised to upgrade to supported versions 5.0.2 or 5.1.1. No active exploitation has been reported as of now. The vulnerability was published on April 10, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-22750 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…