It was reported that if the same hostname already exists in another project when a new route is created, no error handling takes place. While it looks the route in a project has been created successfully, the request made to the route will be sent to the existing service. Attacker may be able to preoccupy a hostname, which stays unnoticed to developer, and users of that service may be led to the malicious site.
Product bug (contains steps to reproduce):
https://bugzilla.redhat.com/show_bug.cgi?id=1302287