Spring Cloud Gateway DoS flaws patched
Multiple vulnerabilities in Spring Cloud Gateway and Cloud Sleuth allow remote denial of service across versions 3.1.x through 5.0.x.
The French national cybersecurity agency ANSSI has published an advisory detailing multiple vulnerabilities in Spring Cloud Gateway and Spring Cloud Sleuth products. The flaws, tracked as CVE-2026-41708 and CVE-2026-47825, allow attackers to trigger remote denial of service conditions. The vendor has also identified an unspecified security issue whose details have not been disclosed.
Affected versions span a wide range of Spring Cloud Gateway releases, from 3.1.x through 5.0.x, as well as Spring Cloud Sleuth 3.1.x series. Organizations running these components should prioritize patching, as the remote exploitability of the denial of service condition presents a clear operational risk.
VMware has released patches addressing these issues. Administrators should upgrade to the fixed versions specified in the vendor security bulletins: Cloud Gateway 3.1.13+, 4.2.9+, 4.3.4.1/4.3.5+, or 5.0.1.1/5.0.2+, and Cloud Sleuth 3.1.14+.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0744
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free