CVE-2026-46579
published 2026-05-29CVE-2026-46579: A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*`…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.33%
25.5th percentile
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift4 | ose-haproxy-router | — | — |
| openshift4 | ose-haproxy-router-rhel9 | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
vendor_redhat·2026-04-17·CVSS 7.4
CVE-2026-46579 [HIGH] CWE-287 openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.
Package: openshift4/ose-haproxy-router (Red Hat OpenShift Container Platform 4) - Affected
Package: openshift4/ose-haproxy-router-rhel9 (Red Hat OpenShift Container Platform 4) - Affected
GHSA
GHSA-ccmj-8c3p-4qwj: A flaw was found in the OpenShift Router
ghsa_unreviewed·2026-05-29
CVE-2026-46579 [HIGH] CWE-287 GHSA-ccmj-8c3p-4qwj: A flaw was found in the OpenShift Router
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:27009https://access.redhat.com/errata/RHSA-2026:27044https://access.redhat.com/errata/RHSA-2026:27063https://access.redhat.com/errata/RHSA-2026:37580https://access.redhat.com/errata/RHSA-2026:40022https://access.redhat.com/errata/RHSA-2026:40828https://access.redhat.com/security/cve/CVE-2026-46579https://bugzilla.redhat.com/show_bug.cgi?id=2483181https://access.redhat.com/errata/RHSA-2026:27009https://access.redhat.com/errata/RHSA-2026:27044https://access.redhat.com/errata/RHSA-2026:27063https://access.redhat.com/errata/RHSA-2026:37580https://access.redhat.com/errata/RHSA-2026:40022https://access.redhat.com/errata/RHSA-2026:40828https://access.redhat.com/security/cve/CVE-2026-46579https://bugzilla.redhat.com/show_bug.cgi?id=2483181https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46579.json
2026-05-29
Published