THREAT OPS › Threat News › [NVD] CVE-2026-1784 (HIGH 8.8) — The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration
[NVD] CVE-2026-1784 (HIGH 8.8) — The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration
CVE-2026-1784 CVSS: 8.8 HIGH Published: 2026-06-02T09:16:15.683
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
Indicators of compromise
- CVE-2026-1784cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1784