WebSocket Control Bypass in Ocelot by ThreeMammals
⚠️ CVE-Referenzen:
CVE-2026-58172
Threemammals - Ocelot - CRITICAL - CVE-2026-58172.
Ocelot, a popular API Gateway developed by ThreeMammals, is vulnerable to a security control bypass that impacts versions up to 24.1.0. This vulnerability arises from the WebSocket upgrade requests that can bypass IP-based access restrictions due to faulty configuration in the OcelotPipelineExtensions.cs file. Specifically, the pipeline omits the crucial SecurityMiddleware layer for these requests, which allows clients from blocked IP addresses to access downstream services without adhering to the pre-configured allow/block list.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io