Bug 2524897 (CVE-2026-81303)

Summary: CVE-2026-81303 hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routeHostName
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abrianik, ggrzybek, jraez, parichar, security-response-team, tasato
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-27 09:53:50 UTC
H-2 from Project Glasswing security audit of hawtio-operator. The operator holds routes/custom-host:create cluster-wide and writes the tenant-supplied spec.routeHostName verbatim into Route.Spec.Host. A namespace edit user who normally cannot set custom Route hosts can launder the request through the operator, enabling subdomain takeover and OAuth redirect hijack. Source: hawtio-operator-security-audit.json#H-2.