CVE-2026-46579

HIGH

Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend

Title source: cna
STIX 2.1

Description

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

References (12)

Core 12
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27009
https://access.redhat.com/errata/RHSA-2026:27009
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27044
https://access.redhat.com/errata/RHSA-2026:27044
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:27063
https://access.redhat.com/errata/RHSA-2026:27063
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-46579
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2483181
https://bugzilla.redhat.com/show_bug.cgi?id=2483181
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:37580
https://access.redhat.com/errata/RHSA-2026:37580
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:40828
https://access.redhat.com/errata/RHSA-2026:40828
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:40022
https://access.redhat.com/errata/RHSA-2026:40022
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:43227
https://access.redhat.com/errata/RHSA-2026:43227
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:43253
https://access.redhat.com/errata/RHSA-2026:43253
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:43331
https://access.redhat.com/errata/RHSA-2026:43331

Scores

CVSS v3 7.4
EPSS 0.0034
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (14)
Red Hat/Red Hat OpenShift Container Platform 4
Red Hat/Red Hat OpenShift Container Platform 4.13 1784056734
Red Hat/Red Hat OpenShift Container Platform 4.14 1784587649
Red Hat/Red Hat OpenShift Container Platform 4.15 1784580646
Red Hat/Red Hat OpenShift Container Platform 4.16 1784331638
Red Hat/Red Hat OpenShift Container Platform 4.18 1783719377
Red Hat/Red Hat OpenShift Container Platform 4.19 1783445642
Red Hat/Red Hat OpenShift Container Platform 4.2 1781639027
Red Hat/Red Hat OpenShift Container Platform 4.20 1781639027
Red Hat/Red Hat OpenShift Container Platform 4.21 1781552170
... and 4 more
Published May 29, 2026
Tracked Since May 29, 2026