Junglewise Threat Intelligence

CVE-2026-42965: Red Hat OpenShift Router SSRF in FQDN EndpointSlice

CVE-2026-42965 · Severity: high · CVSS 7.7 · Published 2026-05-29

Vendors: Red Hat.

Executive brief

A security vulnerability in the Red Hat OpenShift Router allows an authorized user to trick the system into revealing sensitive cloud infrastructure information. By misconfiguring internal networking components, an attacker can gain access to cloud metadata and instance credentials that should be restricted. This could lead to a broader compromise of the cloud environment where the OpenShift cluster is running.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the OpenShift Router due to improper validation of backend destinations resolved from FQDN-typed EndpointSlices. While the router validates IPv4/IPv6 addresses, it fails to perform similar checks on FQDN endpoints that resolve to restricted IP addresses like 169.254.169.254. An attacker with 'write' permissions for EndpointSlices can create a Service backed by a malicious FQDN and a corresponding Route to proxy requests to the cloud metadata service. Because the router often runs with host networking at Layer 7, it can facilitate the token exchange required by IMDSv2, leading to the disclosure of sensitive instance credentials. This attack primarily affects IngressControllers using HostNetwork endpoint publishing.

Affected products

  • Red Hat OpenShift Router unspecified

Timeline

  • 2026-05-29: disclosed: Vulnerability reported and published to NVD

References

Related threats