SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-46579

HIGH · CVSS 7.4 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-46579
Severity
HIGH
CVSS
7.4
EPSS
0.34%

Original NVD Description

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

Related CVEs

Other vulnerabilities affecting the same vendor(s)