Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-1784: OpenShift Route Allows Uncontrolled HAProxy Configuration Injection

CVE-2026-1784 CVE-2026-1784
Summary

An OpenShift Route can inject malicious HAProxy settings, potentially compromising security. This affects OpenShift users who rely on Route resources to expose their applications. To mitigate, review and validate Route configurations to prevent unauthorized HAProxy settings.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
red hat red hat openshift container platform 4.13 All versions
red hat red hat openshift container platform 4.14 All versions
red hat red hat openshift container platform 4.15 All versions
red hat red hat openshift container platform 4.16 All versions
red hat red hat openshift container platform 4.18 All versions
red hat red hat openshift container platform 4.19 All versions
red hat red hat openshift container platform 4.20 All versions
red hat red hat openshift container platform 4.21 All versions
redhat openshift_container_platform 4.0
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
red hat red hat openshift container platform 4.2 All versions
Original title
Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection
Original description
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
nvd CVSS3.1 8.8
Vulnerability type
CWE-15
Published: 2 Jun 2026 · Updated: 22 Jul 2026 · First seen: 2 Jun 2026