boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-46579HIGH
Red Hat Red Hat OpenShift Container Platform 4.12 — Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0035   28.5     —
AFFECTED
  Product                                    Versions     Fixed
  Red Hat OpenShift Container Platform 4.12  unspecified  1784323891
  Red Hat OpenShift Container Platform 4.13  unspecified  1784056734
  Red Hat OpenShift Container Platform 4.14  unspecified  1784587649
  Red Hat OpenShift Container Platform 4.15  unspecified  1784580646
  Red Hat OpenShift Container Platform 4.16  unspecified  1784331638
  Red Hat OpenShift Container Platform 4.17  unspecified  1784321465
  Red Hat OpenShift Container Platform 4.18  unspecified  1783719377
  Red Hat OpenShift Container Platform 4.19  unspecified  1783445642
  Red Hat OpenShift Container Platform 4.20  unspecified  1781639027
  Red Hat OpenShift Container Platform 4.21  unspecified  1781552170
  + 1 more
TIMELINE
  May 28  Reserved by redhat
  May 29  Published (CNA: redhat)
  Aug 17  RESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD).
CWE-287 · CNA: redhat · CVSS v3.1 · 14 references · NVD status: Modified

Description

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 28, 2026ReservedReserved by redhat
May 29, 2026PublishedPublished (CNA: redhat)
August 17, 2026RESCOREDRESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD).

Affected

Affected products and packages — 11 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat OpenShift Container Platform 4.121784323891
Red HatRed Hat OpenShift Container Platform 4.131784056734
Red HatRed Hat OpenShift Container Platform 4.141784587649
Red HatRed Hat OpenShift Container Platform 4.151784580646
Red HatRed Hat OpenShift Container Platform 4.161784331638
Red HatRed Hat OpenShift Container Platform 4.171784321465
Red HatRed Hat OpenShift Container Platform 4.181783719377
Red HatRed Hat OpenShift Container Platform 4.191783445642
Red HatRed Hat OpenShift Container Platform 4.201781639027
Red HatRed Hat OpenShift Container Platform 4.211781552170
Red HatRed Hat OpenShift Container Platform 4.221781643967

Weaknesses

CWE-287

References (14)

Related

Authoritative record: CVE-2026-46579 at cve.org

Vendors: red hat

Weaknesses: CWE-287

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-46579 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.