CVE-2026-7366
Received
Received - Intake
Race Condition in IBM DataPower Gateway Leads to IP Spoofing
Vulnerability report for CVE-2026-7366, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-12
Last updated on: 2026-08-12
Assigner: IBM Corporation
Description
Description
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the builtβin XβClientβIP header. Under concurrent request processing, XβClientβIP values may be contaminated across requests, enabling IP spoofing and disclosure of other clientsβ IP addresses.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | datapower_gateway | From 11.0.0 (inc) to 11.0.0.1 (inc) |
| ibm | datapower_gateway | From 10.5.0 (inc) to 10.5.0.21 (inc) |
| ibm | datapower_gateway | From 10.6.0 (inc) to 10.6.0.9 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-362 | The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently. |