org.springframework.cloud:spring-cloud-gateway-server vulnerabilities

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.springframework.cloud:spring-cloud-gateway-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Expression Language Injection

[,4.2.6)[4.3.0,4.3.2)
  • C
Expression Language Injection

[,4.2.5)[4.3.0,4.3.1)
  • H
Unintended Proxy or Intermediary ('Confused Deputy')

[,3.1.10)[4.0.0,4.1.8)[4.2.0,4.2.3)
  • C
Arbitrary Code Injection

[,3.0.7)[3.1.0,3.1.1)
  • H
HTTP Request Smuggling

[3.0.0,3.0.5)[,2.2.10.RELEASE)

Package versions

55 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
4.3.215 Oct, 2025
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
4.3.18 Sep, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.3.029 May, 2025
  • 1
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.2.615 Oct, 2025
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
4.2.58 Sep, 2025
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.2.410 Jul, 2025
  • 1
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.2.328 May, 2025
  • 1
    C
  • 1
    H
  • 0
    M
  • 0
    L
4.2.23 Apr, 2025
  • 1
    C
  • 2
    H
  • 0
    M
  • 0
    L
4.2.118 Mar, 2025
  • 1
    C
  • 2
    H
  • 0
    M
  • 0
    L
4.2.03 Dec, 2024
  • 1
    C
  • 2
    H
  • 0
    M
  • 0
    L