Gateway
This hub aggregates every CVE we track for Gateway, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
79
CVEs tracked
14
Critical
36
High
4
In CISA KEV
Severity distribution
HIGH36MEDIUM29CRITICAL14
Monthly trend
0
0
0
0
1
0
1
0
0
2
0
3
0
0
1
1
1
0
3
0
0
6
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Gateway.
- CVE-2026-13474Denial of service via malformed HTTP/2 requests7.5
- CVE-2026-10817Insufficient input validation leading to memory overread7.5
- CVE-2026-10816Arbitrary File Read (Unauthenticated)7.5
- CVE-2026-8655Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service9.8
- CVE-2026-8452Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service9.8
- CVE-2026-8451Insufficient input validation leading to memory overread7.5
- CVE-2026-3055Insufficient input validation leading to memory overreadKEV9.8
- CVE-2026-4368Race Condition leading to User Session Mixup8.8
- CVE-2026-32621Apollo Federation has prototype pollution via incomplete key sanitization9.9
- CVE-2026-22771Envoy Extension Policy lua scripts injection causes arbitrary command execution8.8
- CVE-2025-66405Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host9.8
- CVE-2025-12101Cross-Site Scripting (XSS)8.8
- CVE-2025-8424Improper access control on the NetScaler Management Interface9.6
- CVE-2025-7776Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service9.8
- CVE-2025-7775Memory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceKEV9.8
Product normalization is registry-driven with AI assist and human review. How it works