CVE-2026-46579
EUVD-2026-3327429.05.2026, 11:16
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_container_platform | 4.0 |
| redhat | openshift_router | - |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1784323891 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1784056734 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1784587649 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1784580646 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1784331638 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1784321465 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1783719377 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1783445642 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.2 | 1781639027 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1781552170 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1781643967 ≤ 𝑥 < * | ADP |
Common Weakness Enumeration
References