IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7282296 | Vendor Advisory |
Configurations
History
10 Aug 2026, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7282296 - Vendor Advisory | |
| First Time |
Ibm
Ibm application Gateway Operator |
|
| CPE | cpe:2.3:a:ibm:application_gateway_operator:*:*:*:*:*:*:*:* |
05 Aug 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-05 17:16
Updated : 2026-08-10 17:40
NVD link : CVE-2026-17617
Mitre link : CVE-2026-17617
CVE.ORG link : CVE-2026-17617
JSON object : View
Products Affected
ibm
- application_gateway_operator
CWE
CWE-918
Server-Side Request Forgery (SSRF)
