---
id: CVE-2026-7366
title: >-
  IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway
  10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9
  allows a race condition that results in improper isolation of request state
  when han…
summary: >-
  IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway
  10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9
  allows a race condition that results in improper isolation of request state
  when han…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-362
vendor: ibm
product: datapower_gateway
affected:
  - 'datapower_gateway >= 10.5.0.0, < 10.5.0.22'
  - 'datapower_gateway >= 10.6.0.0, < 10.6.0.10'
  - 'datapower_gateway >= 11.0.0.0, < 11.0.0.2'
patched:
  - datapower_gateway 11.0.0.2
published: '2026-08-12'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T18:16:34.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7366'
references:
  - url: 'https://www.ibm.com/support/pages/node/7282770'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00164
epssPercentile: 0.05021
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T13:04:29.122885Z'
ingestedAt: '2026-10-04T18:02:47.903Z'
---

## Overview

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.

## Affected

- `datapower_gateway >= 10.5.0.0, < 10.5.0.22`
- `datapower_gateway >= 10.6.0.0, < 10.6.0.10`
- `datapower_gateway >= 11.0.0.0, < 11.0.0.2`

## Remediation

Upgrade past the affected range:

- `datapower_gateway 11.0.0.2`
