CVE-2026-22750Disclosure(vmware / spring_cloud_gateway)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_cloud_gateway systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not an enterprise customer, you can upgrade to any Spring Cloud Gateway 4.2.x release newer than 4.2.0  available on Maven Centeral https://repo1.maven.org/maven2/org/springframework/cloud/spring-cloud-gateway/ . Ideally if you are not an enterprise customer, you should be upgrading to 5.0.2 or 5.1.1 which are the current supported open source releases.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-15

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_cloud_gateway

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-04-10); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
spring_cloud_gateway

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-04-09: 1Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-10: 4Technical Details · 2026-04-13: 1Technical Details · 2026-04-20: 104-0904-1004-1104-1304-1404-20
Signal classification2 categories
Disclosure
666.7%
Patch
333.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-104
Disclosure3Patch1
2026-04-111
Disclosure1
2026-04-131
Patch1
2026-04-141
Disclosure1
2026-04-201
Patch1
Full discourse9 posts
  • Spring Cloud@springcloud
    Disclosure

    If you are using Spring Cloud Gateway 4.2.0, there is a new CVE report that impacts that specific version. Please see this security advisory for more information: https://spring.io/security/cve-2026-22750

    Post summary

    The text announces a new CVE that affects Spring Cloud Gateway version 4.2.0 and directs readers to a security advisory for further details.

    1511942.5K
    51.4K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Spring ❗ CVE-2026-22750 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-spring-4/ https://t.co/sZhPS8GMU4

    Post summary

    The tweet announces a new vulnerability (CVE‑2026‑22750) affecting Spring products and links to additional information, but provides no technical or exploit details.

    0002083
    6.7K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-22750 (CVSS 7.5) Spring Cloud Gateway SSL config silently ignored, using insecure defaults instead. Affects 4.2.0 & earlier. Upgrade to 5.0.2+ or 5.1.1+ immediately. #CVE #Vulnerability #PatchNow #SpringBoot https://t.co/I4xRj1b3tM

    Post summary

    The tweet discloses CVE‑2026‑22750 in Spring Cloud Gateway, details its CVSS score and impact, and urges users to upgrade to patched versions immediately.

    0000064
    26 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: CVE-2026-22750 flaw in VMware Tanzu Spring Cloud Gateway silently ignores spring.ssl.bundle configs, forces default TLS in 4.2.0 and earlier - upgrade to 4.2.1, 5.0.2 or 5.1.1. https://threatcluster.io/cluster/cve-2026-22750-ssl-configuration-error-in-spring-cloud-gatew-072a32de

    Post summary

    The post alerts about CVE‑2026‑22750 in VMware Tanzu Spring Cloud Gateway that disrupts TLS configuration and advises users to upgrade to patched versions 4.2.1, 5.0.2, or 5.1.1.

    0000028
    149 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-22750 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22750 #CVE-2026-22750 #CVE #High #CyberSecurity #InfoSec https://t.co/UrurwkyMUp

    Post summary

    A tweet announcing CVE‑2026‑22750 with severity and risk level but lacking technical details, exploit information, or mitigation steps.

    0000039
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22750 When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL… https://www.cve.org/CVERecord?id=CVE-2026-22750

    Post summary

    The post announces CVE‑2026‑22750, explaining that the spring.ssl.bundle configuration is ignored in Spring Cloud Gateway, resulting in a fallback to default SSL settings. No PoC, exploit, patch, or active exploitation is mentioned.

    0000088
    57.0K followersView on X
  • dbugs@ptdbugs
    Patch

    SSL bundle configuration silently bypassed in Spring Cloud Gateway CVE: CVE-2026-22750 PT ID: PT-2026-31891 PT-Identifier: PT-2026-31891 Vendor: Vmware Product: Spring Cloud Gateway CVSS: 7.5 Credits: n/a Description: When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not an enterprise customer, you can upgrade to any Spring Cloud Gateway 4.2.x release newer than 4.2.0 available on Maven Centeral https://repo1.maven.org/maven2/org/springframework/cloud/spring-cloud-gateway/ . Ideally if you are not an enterprise customer, you should be upgrading to 5.0.2 or 5.1.1 which are the current supported open source releases. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-22750 • https://spring.io/security/cve-2026-22750 #dbugs_vuln

    Post summary

    CVE-2026-22750 causes Spring Cloud Gateway to silently ignore user-configured SSL bundles, defaulting to standard SSL; upgrading to a supported release resolves the issue.

    00000112
    788 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22750 - SSL bundle configuration silently bypassed in Spring Cloud Gateway Intel Report: https://ift.tt/Fj5stnW

    Post summary

    The alert announces CVE-2026-22750, describing an SSL bundle configuration bypass in Spring Cloud Gateway and referring to an intel report, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0000039
    280 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-22750: SSL bundle configuration silent... Silent SSL config bypass means your gateway's crypto is weaker than you think - perfect for MitM attacks against unsusp... https://zerodaysignal.com/vulnerability/CVE-2026-22750 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑22750, stressing a silent SSL bundle configuration bypass that could weaken gateway cryptography and enable MitM attacks. It provides the vulnerability name and a link to a vulnerability page but contains no PoC, exploit code, or patch details.

    0000063
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_cloud_gateway4.2.0--

Explore more