CVE-2020-5401
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.45%
- CWE
- CWE-393
- Published
- 2020-02-27
- Last modified
- 2026-03-14
Affected products
- Cloud Foundry Routing
Weakness type
Related vulnerabilities
- CVE-2026-55958 — Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
- CVE-2026-9058 — Improper Certificate Verification in Szafir SDK
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2025-24531 — In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error...
- CVE-2025-5987 — Libssh: invalid return code for chacha20 poly1305 with openssl backend
- CVE-2025-32414 — In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the...
- CVE-2024-49117 — Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2023-37897 — Server-side Template Injection (SSTI) in grav