漏洞概述 漏洞编号: CVE-2026-46579 漏洞标题: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend 报告时间: 2026-05-29 09:28 UTC by OSIDB Bzreport 修改时间: 2026-05-29 09:48 UTC 状态: NEW 别名: CVE-2026-46579 产品: Security Response 组件: vulnerability 版本: unspecified 硬件: All 操作系统: Linux 优先级: high 严重性: high 目标里程碑: --- 分配给: Product Security DevOps Team QA联系人: --- 文档联系人: --- URL: --- 白板: --- 依赖项: --- 树视图: depends on / blocked 影响范围 环境: --- 最后关闭: --- 已屏蔽: --- 修复方案 修复版本: --- 关闭日期: --- 详细描述 描述: The OpenShift Router's HAProxy configuration template sets X-SSL-Client- headers (DN, DER, NotAfter, NotBefore, SHA1, Subject) on the HTTP Frontend (Fe_no) using values from the actual TLS handshake. However, the HTTP Frontend (Fe_http) does not strip these headers from incoming requests. When a Route has InsecureEdgeTerminationPolicy set to Allow, an attacker can send plain HTTP requests with forged X-SSL-Client- headers that are forwarded to the backend unmodified. Backends that rely on these headers for mutual TLS authentication can be completely bypassed, allowing an unauthenticated attacker to impersonate any client certificate identity. 附件 附件链接: Terms of Use 备注 备注: You need to log in before you can comment on or make changes to this bug. 其他信息 关键词: Security CC列表: 0 users 页脚 隐私政策: Privacy 联系: Contact 常见问题: FAQ 法律: Legal