Junglewise Threat Intelligence

CVE-2026-46579: Red Hat OpenShift Router mTLS bypass via unstripped HTTP headers

CVE-2026-46579 · Severity: high · CVSS 7.4 · Published 2026-05-29

Vendors: Red Hat.

Executive brief

A security flaw in the Red Hat OpenShift Router allows unauthorized users to bypass identity checks. The router, which manages traffic entering an OpenShift cluster, fails to remove specific security headers from unencrypted web requests. This allows an attacker to forge digital certificate information, potentially gaining access to sensitive internal systems that believe they are communicating with a verified, trusted user.

Technical details

The OpenShift Router's HAProxy configuration fails to strip 'X-SSL-Client-*' headers (including DN, DER, and Subject) on the HTTP frontend (fe_http). While HTTPS frontends correctly populate these headers from the TLS handshake, the HTTP frontend allows them to pass through unmodified from the client. If a Route has 'insecureEdgeTerminationPolicy' set to 'Allow', an unauthenticated remote attacker can send plain HTTP requests with forged headers. Backend services that rely on these headers for mutual TLS (mTLS) authentication will process the forged identity, leading to authentication bypass and identity impersonation.

Affected products

  • Red Hat OpenShift Router unspecified

Timeline

  • 2026-05-29: disclosed: Initial disclosure and NVD publication
  • 2026-05-29: advisory: Red Hat security advisory and Bugzilla entry created

References

Related threats