THREAT OPS › Threat News › [NVD] CVE-2026-42965 (HIGH 7.7) — A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests
[NVD] CVE-2026-42965 (HIGH 7.7) — A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests
CVE-2026-42965 CVSS: 7.7 HIGH Published: 2026-05-29T11:16:16.923
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclo
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-42965cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42965