VYPR

AAP Gateway Envoy proxy

by Red Hat

CVEs (1)

  • CVE-2026-12382HigJul 15, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can…