What is CVE-2026-17617?
CVE-2026-17617: IBM Application Gateway Operator versions 22.2 through 26.06 contains a Server-Side Request Forgery (SSRF) vulnerability due to insufficient validation of URLs specified in custom resources. This could allow an attacker to send unauthorized requests to internal networks by manipulating the server; users are advised to apply the provided patch immediately.
Azərbaycanca: CVE-2026-17617: IBM Application Gateway Operator-un 22.2-dən 26.06 versiyalarına qədər olan versiyalarında, xüsusi resurslarda göstərilən URL-lərin kifayət qədər yoxlanılmaması səbəbindən Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. Bu, təcavüzkara serveri manipulyasiya edərək daxili şəbəkəyə icazəsiz sorğular göndərməyə imkan verə bilər; istifadəçilərə verilən yamağı dərhal tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: IBM
FAQ2
Which versions of IBM Application Gateway Operator are affected by CVE-2026-17617?
This SSRF vulnerability affects IBM Application Gateway Operator versions 22.2 through 26.06.
What could an attacker potentially achieve by exploiting CVE-2026-17617?
An attacker could manipulate the server to send unauthorized requests to internal networks by exploiting the insufficient validation of URLs specified in custom resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.