The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
References
Configurations
History
20 Jul 2026, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
02 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://access.redhat.com/errata/RHSA-2026:28893 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:28964 - |
02 Jul 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 03:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://access.redhat.com/errata/RHSA-2026:23241 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:23246 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:25045 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:25182 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:25194 - | |
| References | () https://access.redhat.com/errata/RHSA-2026:26543 - | |
| References | () https://access.redhat.com/security/cve/CVE-2026-1784 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2436075 - Issue Tracking, Vendor Advisory |
25 Jun 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
17 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Jun 2026, 14:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://access.redhat.com/security/cve/CVE-2026-1784 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2436075 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat
Redhat openshift Container Platform |
|
| CPE | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
02 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 09:16
Updated : 2026-07-21 13:17
NVD link : CVE-2026-1784
Mitre link : CVE-2026-1784
CVE.ORG link : CVE-2026-1784
JSON object : View
Products Affected
redhat
- openshift_container_platform
CWE
CWE-15
External Control of System or Configuration Setting
