Skip to content
IBMCVE-2026-7366

IBM DataPower Gateway: race condition

Medium4.2CVE-2026-7366 · Published Aug 12, 2026 · updated Aug 17, 2026

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.

IBM advisory

Affected versions

PackageAffectedFixed in
DataPower Gateway 10.5.0
Product
>= 10.5.0.0, <= 10.5.0.21No fix yet
DataPower Gateway 10.6.0
Product
>= 10.6.0.0, <= 10.6.0.9No fix yet
DataPower Gateway 11.0.0
Product
>= 11.0.0.0, <= 11.0.0.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-362

More IBM advisories

All IBM
Advisory
IBM Db2: buffer overflow
High8.4Aug 12
IBM i: denial of service
High8.2Aug 12
IBM DOORS Next: improper authentication
Critical10.0Aug 12
IBM Db2: improper authorization
Medium4.3Aug 12
IBM i Access Client Solutions: code execution
High7.8Aug 12
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access...
Medium6.8Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.