CVE-2026-1784
Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
02 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Red Hat · Red Hat OpenShift Container Platform 4.13Red Hat · Red Hat OpenShift Container Platform 4.16Red Hat · Red Hat OpenShift Container Platform 4.18Red Hat · Red Hat OpenShift Container Platform 4.19Red Hat · Red Hat OpenShift Container Platform 4.20Red Hat · Red Hat OpenShift Container Platform 4.21¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2026:23241https://access.redhat.com/errata/RHSA-2026:23246https://access.redhat.com/errata/RHSA-2026:25045https://access.redhat.com/errata/RHSA-2026:25182https://access.redhat.com/errata/RHSA-2026:25194https://access.redhat.com/errata/RHSA-2026:26543https://access.redhat.com/security/cve/CVE-2026-1784https://bugzilla.redhat.com/show_bug.cgi?id=2436075