Intel

AIKIDO-2026-10570

spring-cloud-gateway-server is vulnerable to Always-Incorrect Control Flow Implementation

Always-Incorrect Control Flow ImplementationCVE-2026-22750 Published Apr 27, 2026

85

High Risk

This Affects:

JAVAspring-cloud-gateway-server
4.2.0 - 4.2.0
Fixed in 4.2.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper security configuration handling because SSL bundle settings provided through spring.ssl.bundle may be silently ignored, causing Spring Cloud Gateway to fall back to default SSL settings. This can result in unintended trust settings, weakened TLS protections, or connections that do not enforce the administrator’s expected certificate configuration.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-cloud-gateway-server is vulnerable to Always-Incorrect Control Flow Implementation in versions 4.2.0 - 4.2.0.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-gateway-server library to the patch version.