Red HatCVE-2026-12382
Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing
High8.2CVE-2026-12382 · Published Jul 15, 2026 · updated Aug 12, 2026
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
- www.cve.org/CVERecord?id=CVE-2026-12382
- nvd.nist.gov/vuln/detail/CVE-2026-12382
- access.redhat.com/errata/RHSA-2026:13508
- access.redhat.com/errata/RHSA-2026:13545
- access.redhat.com/errata/RHSA-2026:42078
- access.redhat.com/errata/RHSA-2026:42142
- access.redhat.com/security/cve/CVE-2026-12382
- bugzilla.redhat.com/show_bug.cgi?id=2489126
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 15 | Red Hat samba: denial of service | Medium6.1 | No fix yet |
| Jul 15 | Red Hat CRI-O: format string | High7.8 | No fix yet |
| Jul 15 | Red Hat OpenShift GitOps: denial of service | High7.7 | No fix yet |
| Jul 14 | A flaw was found in libsoup's WebSocket implementation | High7.5 | No fix yet |
| Jul 14 | Red Hat libsoup: denial of service | High7.5 | No fix yet |
| Jul 14 | Red Hat libsoup: denial of service | Medium5.9 | No fix yet |