# CVE-2020-5401

## Summary

- **CVE ID:** CVE-2020-5401
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-393
- **Published:** Feb 27, 2020
- **Last Modified:** Mar 14, 2026

## Description

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.

## Affected Products

- Cloud Foundry — Routing (unspecified)

## References

- [CNA](https://www.cloudfoundry.org/blog/cve-2020-5401)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 63.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._