← Vulnerability feed

Vulnerability record · CVE-2022-22946 · published 4 March 2022

CVE-2022-22946: Vmware spring cloud gateway improper certificate validation vulnerability

Vmware · Spring Cloud Gateway

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

5.5 CVSS 3.1 Medium EPSS 4.8% · top 8.3% CWE-295 · Improper certificate validation
5.5CVSS 3.1 base score, v2 2.1
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22946 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-22947Spring Cloud Gateway Actuator endpoint code injectionSpring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A c…KEVEPSS 98%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed9.9CVE-2026-61146Oracle commerce experience manager improper privilege management vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition Sy…EPSS 0.43%9.8CVE-2026-70995Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Con…EPSS 0.51%9.8CVE-2026-61161Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Con…EPSS 0.51%9.8CVE-2026-61145Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition Sy…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2022-22946), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.