{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/application-gateway-operator-22.2-through-26.06/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-17617"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Application Gateway Operator (22.2 through 26.06)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssrf","kubernetes"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Application Gateway Operator versions 22.2 through 26.06 are impacted by a Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-17617. The flaw originates from insufficient validation of URL parameters specified within Kubernetes custom resources processed by the operator. An authenticated user with low-level privileges can manipulate these resources to force the gateway to initiate requests to arbitrary internal or external endpoints. This could lead to sensitive information disclosure or unauthorized interactions with internal services reachable from the gateway's network context. Defenders should audit configurations for the Application Gateway Operator and ensure that only trusted users have the ability to apply custom resource modifications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged attacker to perform unauthorized SSRF attacks, leading to the potential discovery of internal network topology, access to metadata services, or interaction with internal APIs that are otherwise unreachable from the public internet. The vulnerability impacts all deployments of the IBM Application Gateway Operator between versions 22.2 and 26.06.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching to the latest version of IBM Application Gateway Operator as directed by the official IBM security advisory.\u003c/li\u003e\n\u003cli\u003eImplement strict Role-Based Access Control (RBAC) within the Kubernetes cluster to limit the ability to create or modify custom resources associated with the Application Gateway Operator to only highly trusted service accounts or administrators.\u003c/li\u003e\n\u003cli\u003eReview cluster network policies to restrict the egress capabilities of the IBM Application Gateway Operator pods, ensuring they can only communicate with required external or internal dependencies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T17:20:44Z","date_published":"2026-08-05T17:20:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-app-gateway-ssrf/","summary":"IBM Application Gateway Operator versions 22.2 through 26.06 contain a Server-Side Request Forgery vulnerability due to improper URL validation in custom resources, potentially allowing unauthorized access to internal resources.","title":"SSRF Vulnerability in IBM Application Gateway Operator","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-app-gateway-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Application Gateway Operator (22.2 Through 26.06)","version":"https://jsonfeed.org/version/1.1"}