CVE-2026-17617

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
05/08/2026
Last modified:
10/08/2026

Description

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:application_gateway_operator:*:*:*:*:*:*:*:* 22.2.0 (including) 26.6.0 (including)


References to Advisories, Solutions, and Tools