VYPR

MaaS API

by Red Hat

CVEs (1)

  • CVE-2026-14450CriAug 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication…