# Spring Cloud Gateway DoS flaws patched

Published: 2026-06-12 · Severity: medium
Canonical: https://vorant.io/reports/626816bd-c00b-454e-8c4b-4166ce03ec88/spring-cloud-gateway-dos-flaws-patched

> Multiple vulnerabilities in Spring Cloud Gateway and Cloud Sleuth allow remote denial of service across versions 3.1.x through 5.0.x.

The French national cybersecurity agency ANSSI has published an advisory detailing multiple vulnerabilities in Spring Cloud Gateway and Spring Cloud Sleuth products. The flaws, tracked as CVE-2026-41708 and CVE-2026-47825, allow attackers to trigger remote denial of service conditions. The vendor has also identified an unspecified security issue whose details have not been disclosed.

Affected versions span a wide range of Spring Cloud Gateway releases, from 3.1.x through 5.0.x, as well as Spring Cloud Sleuth 3.1.x series. Organizations running these components should prioritize patching, as the remote exploitability of the denial of service condition presents a clear operational risk.

VMware has released patches addressing these issues. Administrators should upgrade to the fixed versions specified in the vendor security bulletins: Cloud Gateway 3.1.13+, 4.2.9+, 4.3.4.1/4.3.5+, or 5.0.1.1/5.0.2+, and Cloud Sleuth 3.1.14+.

## Mentioned in this report

- Vulnerabilities: CVE-2026-41708, CVE-2026-47825

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0744

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/626816bd-c00b-454e-8c4b-4166ce03ec88/spring-cloud-gateway-dos-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
