VDB
CVE-2026-42965
CVE-2026-42965
PUBLISHED
CVSS 7.7 HIGH
Reported by redhat · Published May 29, 2026
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.
Risk Scores
CVSS 3.1
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786771399 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786496552 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786498169 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786584196 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786584196, 1786584196, 1786584196 |
| Red Hat | Red Hat OpenShift Container Platform 5 | |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786498169, 1786498169, 1786498169 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786498169, 1786498169, 1786498169 |
| Red Hat | Red Hat OpenShift Container Platform 4.2 | 1786496552, 1786496552 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786496552, 1786496552, 1786496552 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786771399, 1786771399 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786584196, 1786584196, 1786584196 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786771399 |
| Red Hat | Red Hat OpenShift Container Platform 4.2 | 1786496552, 1786496552 |
…and 1 more
Timeline
- May 29, 2026 EPSS Score
- May 29, 2026 CVE Published
- May 29, 2026 CVE Updated
- May 30, 2026 EPSS Score
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 2, 2026 Security Advisory
- Jun 5, 2026 EPSS Score
- Jun 8, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 20, 2026 Distribution Patch
- Aug 20, 2026 Distribution Patch
References
- RHSA-2026:54583 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54602 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54770 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:57408 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2483184 issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42965.json url