CVE-2026-46579
HIGHOpenshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
Title source: cnaDescription
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.
References (12)
Core 12
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27009
https://access.redhat.com/errata/RHSA-2026:27009
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27044
https://access.redhat.com/errata/RHSA-2026:27044
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:27063
https://access.redhat.com/errata/RHSA-2026:27063
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-46579
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2483181
https://bugzilla.redhat.com/show_bug.cgi?id=2483181
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:37580
https://access.redhat.com/errata/RHSA-2026:37580
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:40828
https://access.redhat.com/errata/RHSA-2026:40828
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:40022
https://access.redhat.com/errata/RHSA-2026:40022
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:43227
https://access.redhat.com/errata/RHSA-2026:43227
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:43253
https://access.redhat.com/errata/RHSA-2026:43253
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:43331
https://access.redhat.com/errata/RHSA-2026:43331
Scores
CVSS v3
7.4
EPSS
0.0034
EPSS Percentile
26.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (14)
Red Hat/Red Hat OpenShift Container Platform 4
Red Hat/Red Hat OpenShift Container Platform 4.13
1784056734
Red Hat/Red Hat OpenShift Container Platform 4.14
1784587649
Red Hat/Red Hat OpenShift Container Platform 4.15
1784580646
Red Hat/Red Hat OpenShift Container Platform 4.16
1784331638
Red Hat/Red Hat OpenShift Container Platform 4.18
1783719377
Red Hat/Red Hat OpenShift Container Platform 4.19
1783445642
Red Hat/Red Hat OpenShift Container Platform 4.2
1781639027
Red Hat/Red Hat OpenShift Container Platform 4.20
1781639027
Red Hat/Red Hat OpenShift Container Platform 4.21
1781552170
... and 4 more
Published
May 29, 2026
Tracked Since
May 29, 2026