boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-46579

Red Hat Red Hat OpenShift Container Platform 4.12 — Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0062   48.0     —
AFFECTED
  Product                                    Versions     Fixed
  Red Hat OpenShift Container Platform 4.12  unspecified  1784323891
  Red Hat OpenShift Container Platform 4.13  unspecified  1784056734
  Red Hat OpenShift Container Platform 4.14  unspecified  1784587649
  Red Hat OpenShift Container Platform 4.15  unspecified  1784580646
  Red Hat OpenShift Container Platform 4.16  unspecified  1784331638
  Red Hat OpenShift Container Platform 4.17  unspecified  1784321465
  Red Hat OpenShift Container Platform 4.18  unspecified  1783719377
  Red Hat OpenShift Container Platform 4.19  unspecified  1783445642
  Red Hat OpenShift Container Platform 4.20  unspecified  1781639027
  Red Hat OpenShift Container Platform 4.21  unspecified  1781552170
  + 1 more
TIMELINE
  May 28  Reserved by redhat
  May 29  Published (CNA: redhat)
  Aug 17  RESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD).
CWE-287 · CNA: redhat · CVSS v3.1 · 14 references · NVD status: Modified

Description

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 28, 2026ReservedReserved by redhat
May 29, 2026PublishedPublished (CNA: redhat)
August 17, 2026RESCOREDRESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD).

Affected

Affected products and packages — 11 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat OpenShift Container Platform 4.12——1784323891
Red HatRed Hat OpenShift Container Platform 4.13——1784056734
Red HatRed Hat OpenShift Container Platform 4.14——1784587649
Red HatRed Hat OpenShift Container Platform 4.15——1784580646
Red HatRed Hat OpenShift Container Platform 4.16——1784331638
Red HatRed Hat OpenShift Container Platform 4.17——1784321465
Red HatRed Hat OpenShift Container Platform 4.18——1783719377
Red HatRed Hat OpenShift Container Platform 4.19——1783445642
Red HatRed Hat OpenShift Container Platform 4.20——1781639027
Red HatRed Hat OpenShift Container Platform 4.21——1781552170
Red HatRed Hat OpenShift Container Platform 4.22——1781643967

Weaknesses

CWE-287

References (14)

Related

Authoritative record: CVE-2026-46579 at cve.org

Vendors: red hat

Weaknesses: CWE-287

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-46579 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.