Junglewise Threat Intelligence

CVE-2026-17617: IBM Application Gateway Operator SSRF in custom resource validation

CVE-2026-17617 · Severity: high · CVSS 8.5 · Published 2026-08-05

Vendors: IBM.

Executive brief

IBM Application Gateway Operator is a Kubernetes component used to manage application access and network policies. Versions 22.2 through 26.06 contain a server-side request forgery (SSRF) vulnerability that allows attackers to make unauthorized requests to internal systems and services by specifying malicious URLs in configuration resources, potentially leading to data exposure or lateral movement within the infrastructure.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw stemming from insufficient validation of URLs specified in custom resources processed by the Operator. An attacker with access to create or modify custom resources in the Kubernetes cluster can specify arbitrary URLs that the Operator will request, allowing the attacker to probe or interact with internal systems that may not be directly accessible from the network. The attack requires cluster-level access to deploy or modify custom resources. This vulnerability affects all versions from 22.2 through 26.06; patches or version updates are likely available from IBM.

Affected products

  • IBM Application Gateway Operator 22.2 through 26.06

Timeline

  • 2026-08-05: disclosed

References