Network Traffic Redirection Vulnerability in Submariner by Red Hat
CVE-2026-66785
2.5LOW
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-66785?
A vulnerability exists in Submariner that enables a malicious cluster to misdirect network traffic from connected peer clusters. By incorrectly validating network subnets, an attacker can create a fabricated network endpoint that declares arbitrary network ranges. As a result, any traffic directed to these ranges is rerouted through the attacker's tunnel, which could lead to potential information leaks or disruption of network services.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023940
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072