PT-2026-53923 · Ocelot · Ocelot

·

CVE-2026-58172

·

Published

2026-06-30

·

Updated

2026-07-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ocelot versions prior to 24.1.1
Description A security control bypass exists in the handling of WebSocket upgrade requests. The issue stems from a logic flaw in the OcelotPipelineExtensions.cs file, where a MapWhen branch configured for WebSocket upgrades omits the SecurityMiddleware. This omission allows clients from blocked IP addresses to circumvent configured IP-based access restrictions and have their traffic proxied to downstream services, potentially leading to unauthorized access and data exposure.
Recommendations Update to the version containing commit f156fd4.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58172

Affected Products

Ocelot