Skip to content
Red HatCVE-2026-12382

Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing

High8.2CVE-2026-12382 · Published Jul 15, 2026 · updated Aug 12, 2026

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat samba: denial of service
Medium6.1Jul 15
Red Hat CRI-O: format string
High7.8Jul 15
Red Hat OpenShift GitOps: denial of service
High7.7Jul 15
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.