CVE-2026-22726Disclosure(cloudfoundry / cf-deployment)

LOWCVSS 5.0 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application. Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.372.0 or greater. CF Deployment: affected from v0.0.2 through v54.14.0 (inclusive); upgrade to v55.0.0 or greater (includes routing_release v0.372.0).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-923

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cf-deployment
  • routing_release

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Products
cf-deploymentrouting_release

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-01: 4Technical Details · 2026-05-01: 305-01
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22726 Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with acces… https://www.cve.org/CVERecord?id=CVE-2026-22726 ----- Traducción: CVE-2026-22726 Los… http://infoflow.cloud`

    Post summary

    The tweet offers a brief disclosure of CVE-2026-22726, describing how Route Services could allow traffic to bypass configured egress restrictions.

    0000018
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22726 Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with acces… https://www.cve.org/CVERecord?id=CVE-2026-22726

    Post summary

    The text announces CVE-2026-22726, detailing how Route Services can bypass egress rules but does not provide PoC, exploit, patch, or evidence of active exploitation.

    00000165
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-22726 📊 Severity: 5.0 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22726 #CVE-2026-22726 #CVE #Medium #CyberSecurity #InfoSec https://t.co/0KCh3zPwpO

    Post summary

    The tweet announces CVE-2026‑22726, lists its medium severity and unspecified product impact, and provides only a link to the NVD entry without any PoC, exploit, or mitigation details.

    0000024
    151 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22726 Unauthorized Internal Network Access via Route Services in Cloud Foundry https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22726

    Post summary

    The text announces CVE‑2026‑22726, highlighting unauthorized internal network access via Route Services in Cloud Foundry and provides a short description of the issue. No exploit code, patch links, or evidence of active exploitation is mentioned.

    0000037
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudfoundrycf-deployment---
Appcloudfoundryrouting_release---

Explore more