CVE Explorer
CVE-2026-22726
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter, which may not have previously had direct access from outside networks, or from the application.
Routing release: affected from v0.118.0 through v0.371.0 (inclusive); upgrade to v0.37
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"Routing release","vendor":"CloudFoundry Foundation","versions":[{"lessThan":"v0.372.0","status":"affected","version":"v0.118.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"CF Deployment","vendor":"CloudFoundry Foundation","versions":[{"lessThan":"v55.0.0","status":"affected","version":"v0.0.2","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"Routing release","vendor":"CloudFoundry Foundation","versions":[{"lessThan":"v0.372.0","status":"affected","version":"v0.118.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"CF Deployment","vendor":"CloudFoundry Foundation","versions":[{"lessThan":"v55.0.0","status":"affected","version":"v0.0.2","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-923","description":"CWE-923: Improper Restriction of Communication Channel to Intended Endpoints","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.cloudfoundry.org/blog/cve-2026-22726-route-services-firewall-bypass/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6835ecaa59826083b5571aa569cb22899c367b6806953535019efcd31db657de · sha256:40ba59408f719e65… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.