IBMCVE-2026-7366
IBM DataPower Gateway: race condition
Medium4.2CVE-2026-7366 · Published Aug 12, 2026 · updated Aug 17, 2026
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| DataPower Gateway 10.5.0 Product | >= 10.5.0.0, <= 10.5.0.21 | No fix yet |
| DataPower Gateway 10.6.0 Product | >= 10.6.0.0, <= 10.6.0.9 | No fix yet |
| DataPower Gateway 11.0.0 Product | >= 11.0.0.0, <= 11.0.0.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-362
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | IBM Db2: buffer overflow | High8.4 | No fix yet |
| Aug 12 | IBM i: denial of service | High8.2 | No fix yet |
| Aug 12 | IBM DOORS Next: improper authentication | Critical10.0 | No fix yet |
| Aug 12 | IBM Db2: improper authorization | Medium4.3 | No fix yet |
| Aug 12 | IBM i Access Client Solutions: code execution | High7.8 | No fix yet |
| Aug 12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access... | Medium6.8 | No fix yet |