CVE-2026-7366
Received Received - Intake

Race Condition in IBM DataPower Gateway Leads to IP Spoofing

Vulnerability report for CVE-2026-7366, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: IBM Corporation

Description

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm datapower_gateway From 11.0.0 (inc) to 11.0.0.1 (inc)
ibm datapower_gateway From 10.5.0 (inc) to 10.5.0.21 (inc)
ibm datapower_gateway From 10.6.0 (inc) to 10.6.0.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in IBM DataPower Gateway versions 11.0.0.0 through 11.0.0.1, 10.5.0.0 through 10.5.0.21, and 10.6.0.0 through 10.6.0.9. It improperly isolates request state when processing the built-in X-Client-IP header. Under concurrent requests, this can cause X-Client-IP values to mix across requests, allowing IP spoofing and exposing other clients' IP addresses.

Detection Guidance

This vulnerability involves a race condition in IBM DataPower Gateway handling the X-Client-IP header. Detection requires checking for improper IP address isolation during concurrent requests. Monitor logs for inconsistent X-Client-IP values across requests or unexpected IP address exposure in responses.

Impact Analysis

This vulnerability may allow attackers to spoof IP addresses, leading to unauthorized access or misattribution of actions. It could also expose sensitive client IP information, potentially compromising privacy or enabling further attacks like session hijacking or bypassing IP-based restrictions.

Compliance Impact

This vulnerability could impact compliance by exposing client IP addresses, which may violate data protection requirements under GDPR or HIPAA. Unauthorized IP disclosure risks breaching confidentiality and privacy obligations, potentially leading to regulatory penalties or legal consequences.

Mitigation Strategies

Apply the latest IBM DataPower Gateway patch immediately. Disable or restrict use of the built-in X-Client-IP header if not required. Implement network-level controls to monitor and block suspicious IP spoofing attempts. Review and update request handling policies to enforce strict isolation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7366. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart