MEDIUM🇵🇱 Wersja polska

CVE-2026-22726

CVSS 5.0v3.1pub. 2026-05-01upd. 2026-05-04

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application. Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.372.0 or greater. CF Deployment: affected from v0.0.2 through v54.14.0 (inclusive); upgrade to v55.0.0 or greater (includes routing_release v0.372.0).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
  • Cloudfoundry Cf Deployment

    APP
    Cloudfoundry
    0.0.2 – 55.0.0 (excl.)
  • Cloudfoundry Routing Release

    APP
    Cloudfoundry
    0.118.0 – 0.372.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-31733CRITICAL9.1PL ✓same product

Cloudfoundry Diego — pominięcie uwierzytelniania mTLS przez niezabezpieczony port

CVE-2019-3801CRITICAL9.8PL ✓same product

Cloud Foundry cf-deployment: wstrzyknięcie kodu przez niezaszyfrowany protokół pobierania zależności

CVE-2023-20881HIGH8.1same product

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may ove...

CVE-2021-22101HIGH7.5same product

Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerabil...

CVE-2021-22001HIGH7.5same product

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in re...