Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-22726— Route Services Firewall Bypass

CVSS 5.0 · Medium EPSS 0.04% · P13
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-22726

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Route Services Firewall Bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application. Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.372.0 or greater. CF Deployment: affected from v0.0.2 through v54.14.0 (inclusive); upgrade to v55.0.0 or greater (includes routing_release v0.372.0).
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
通信信道对预期端点的不适当限制
Source: NVD (National Vulnerability Database)
Vulnerability Title
CloudFoundry CF Deployment 和CloudFoundry Routing release 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CloudFoundry CF Deployment 和CloudFoundry Routing release都是CloudFoundry基金会的产品。CloudFoundry CF Deployment 是一个代码部署组件。CloudFoundry Routing release是一个应用路由组件集合。 CloudFoundry CF Deployment 和CloudFoundry Routing release存在安全漏洞,该漏洞源于路由服务可被利用将应用流量发送到配置的出口规则之外的网络目标,允
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CloudFoundry FoundationRouting release v0.118.0 ~ v0.372.0 -
CloudFoundry FoundationCF Deployment v0.0.2 ~ v55.0.0 -

II. Public POCs for CVE-2026-22726

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-22726

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-22726

No comments yet


Leave a comment