QSearchQSearch

CVE-2026-1784

8.8 HIGH

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy

Published: 2026-06-02 · Last updated: 2026-06-10

Severity and scoring

CVSS
8.8 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-15

Affected products

VendorProduct
redhatopenshift_container_platform

Description

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-50259 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)
  • CVE-2026-50258 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)
  • CVE-2026-50257 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence() (7.8 HIGH)
  • CVE-2026-50256 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)
  • CVE-2026-10533 A flaw was found in OpenShift Container Platform (5.0 MEDIUM)

Same CWE

  • CVE-2026-0418 Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper ...
  • CVE-2026-46399 HAX CMS helps manage microsite universe with PHP or NodeJs backends
  • CVE-2019-25716 Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cau... (6.5 MEDIUM)
  • CVE-2026-45087 Dalfox is a powerful open-source XSS scanner and utility focused on automation (10.0 CRITICAL)
  • CVE-2026-6973 A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remo... (7.2 HIGH)