Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application. Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.372.0 or greater. CF Deployment: affected from v0.0.2 through v54.14.0 (inclusive); upgrade to v55.0.0 or greater (includes routing_release v0.372.0).
History

Mon, 04 May 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry routing Release
CPEs cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:routing_release:*:*:*:*:*:*:*:*
Vendors & Products Cloudfoundry routing Release

Fri, 01 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 May 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry routing-release
Vendors & Products Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry routing-release

Thu, 30 Apr 2026 23:30:00 +0000

Type Values Removed Values Added
Description Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application. Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.372.0 or greater. CF Deployment: affected from v0.0.2 through v54.14.0 (inclusive); upgrade to v55.0.0 or greater (includes routing_release v0.372.0).
Title Route Services Firewall Bypass
Weaknesses CWE-923
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2026-04-30T23:17:00.707Z

Updated: 2026-05-01T14:19:13.594Z

Reserved: 2026-01-09T06:54:41.497Z

Link: CVE-2026-22726

cve-icon Vulnrichment

Updated: 2026-05-01T14:19:10.307Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-01T00:16:23.650

Modified: 2026-05-04T18:30:01.760

Link: CVE-2026-22726

cve-icon Redhat

No data.