CVE-2026-7366

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
References
Link Resource
https://www.ibm.com/support/pages/node/7282770 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 22:17

Updated : 2026-08-17 18:20


NVD link : CVE-2026-7366

Mitre link : CVE-2026-7366

CVE.ORG link : CVE-2026-7366


JSON object : View

Products Affected

ibm

  • datapower_gateway
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')