Skip to main content

External Control of System or Configuration Setting

CVE-2026-1784

Severity High
Score 8.8/10

Summary

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

  • LOW
  • LOCAL
  • HIGH
  • CHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-15 - External Control of System or Configuration Setting

One or more system settings or configuration elements can be externally controlled by a user.

References

Advisory Timeline

  • Published