CVE-2026-46579High· 7.4▾ TwilightA flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send p…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
0.2% → 0.4%
Last analysed / modified upstream
A flaw was found in the OpenShift Router. When a Route has insecureEdgeTerminationPolicy set to Allow, the HTTP frontend does not remove X-SSL-Client-* headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted X-SSL-Client-* headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.
openshift_container_platform = 4.0openshift_routerRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12112High· 7.8A flaw was found in the foreman-mcp-server
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
CVE-2026-18215Medium· 6.8Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant)
CVE-2026-54100High· 8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform