Description
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:23241
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:23246
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:25045
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:25182
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:25194
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:26543
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28893
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28964
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-1784
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2436075
Updated 5m ago · 8 sources