openshift_router vulnerabilities
CVEs whose affected-version data names the openshift_router package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoin…
▾ Twilightredhat · openshift_container_platformEPSS 0.26%via NVD
CVE-2026-46579High· 7.4A flaw was found in the OpenShift Router
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send p…
▾ Twilightredhat · openshift_container_platformEPSS 0.45%via NVD