CVE-2026-22750Vmware · Spring_cloud_gateway
Vulnerability data via NVD (ingested)
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not an enterprise customer, you can upgrade to any Spring Cloud Gateway 4.2.x release newer than 4.2.0 available on Maven Centeral https://repo1.maven.org/maven2/org/springframework/cloud/spring-cloud-gateway/ . Ideally if you are not an enterprise customer, you should be upgrading to 5.0.2 or 5.1.1 which are the current supported open source releases.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-22750product:"Vmware Spring Cloud Gateway" version:"4.2.0"http.html:"Spring Cloud Gateway"More intel sources (5)
vuln:CVE-2026-22750vulnerabilities.cve_id: CVE-2026-22750CVE-2026-22750CVE-2026-22750"CVE-2026-22750" exploit -site:nvd.nist.gov