{"id":"CVE-2026-17617","details":"IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.","modified":"2026-08-12T16:24:51.020639Z","published":"2026-08-05T17:16:44.543Z","references":[{"type":"ADVISORY","url":"https://www.ibm.com/support/pages/node/7282296"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ibm-security/ibm-application-gateway-operator","events":[{"introduced":"6b98039c0de1dee5de1ad8cab6fc305440bee882"},{"last_affected":"4ac37704893ce267fb2fe36c0b30d7dc84627a63"}],"database_specific":{"cpe":"cpe:2.3:a:ibm:application_gateway_operator:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"22.2.0"},{"last_affected":"26.6.0"}],"source":"CPE_RANGE"}}],"versions":["v26.6.0","v25.2.0","v24.4.0","v23.11.0","v22.11.0","v22.3.0","v22.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17617.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}