SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47879

HIGH · CVSS 7.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Spring Cloud Gateway JsonToGrpcGatewayFilterFactory is vulnerable to arbitrary resource location access, allowing attackers to define proto descriptors from unauthorized Spring Resource locations. This could lead to unauthorized access or manipulation of gRPC services, posing a significant risk to applications utilizing affected versions of Spring Cloud Gateway. Organizations using versions 3.1.13 and earlier, as well as 4.x and 5.x series, should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-47879
Severity
HIGH
CVSS
7.7
EPSS
0.25%

Original NVD Description

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)