Executive brief
A security flaw in the Red Hat OpenShift Router allows unauthorized users to bypass identity checks. The router, which manages traffic entering an OpenShift cluster, fails to remove specific security headers from unencrypted web requests. This allows an attacker to forge digital certificate information, potentially gaining access to sensitive internal systems that believe they are communicating with a verified, trusted user.
Technical details
The OpenShift Router's HAProxy configuration fails to strip 'X-SSL-Client-*' headers (including DN, DER, and Subject) on the HTTP frontend (fe_http). While HTTPS frontends correctly populate these headers from the TLS handshake, the HTTP frontend allows them to pass through unmodified from the client. If a Route has 'insecureEdgeTerminationPolicy' set to 'Allow', an unauthenticated remote attacker can send plain HTTP requests with forged headers. Backend services that rely on these headers for mutual TLS (mTLS) authentication will process the forged identity, leading to authentication bypass and identity impersonation.
Affected products
- Red Hat OpenShift Router unspecified
Timeline
- 2026-05-29: disclosed: Initial disclosure and NVD publication
- 2026-05-29: advisory: Red Hat security advisory and Bugzilla entry created