The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 02 Jun 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration. | |
| Title | Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-15 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-02T07:22:26.461Z
Reserved: 2026-02-02T21:17:24.893Z
Link: CVE-2026-1784
No data.
Status : Received
Published: 2026-06-02T09:16:15.683
Modified: 2026-06-02T09:16:15.683
Link: CVE-2026-1784
OpenCVE Enrichment
Updated: 2026-06-02T10:00:06Z
Weaknesses