CVE-2026-58172Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline branch configured via MapWhen in OcelotPipelineExtensions.cs omits SecurityMiddleware, causing requests from blocked IP addresses to be proxied to downstream services without enforcement of the configured allow/block list.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-03: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 106-3007-0107-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-011
Disclosure1
2026-07-031
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-58172 (CVSS 9.1) - Ocelot API Gateway ≤24.1.0 allows IP blocklist bypass via WebSocket upgrade requests. SecurityMiddleware omitted in WebSocket pipeline. Patch: commit f156fd4. #CVE #PatchNow #ThreatIntel https://t.co/nmZ1DZJGfr

    Post summary

    The tweet highlights the critical CVE‑2026‑58172 in Ocelot API Gateway, details the IP blocklist bypass vulnerability, and directs users to a specific patch commit to remediate the flaw.

    0000064
    58 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-58172 - Critical security bypass in #Ocelot ≤24.1.0. Denied clients exploit WebSocket upgrades to bypass IP restrictions, reaching downstream services. #CVSS 9.1. #cybersecurity #redteam #blueteam #cybernews #sysadmin #infosec #linix More: https://www.valtersit.com/cve/CVE-2026-58172

    Post summary

    CVE-2026-58172 exposes a critical security bypass in Ocelot, where denied clients can use WebSocket upgrades to evade IP restrictions and reach downstream services. The vulnerability carries a high CVSS 9.1 score, with no active exploitation or patch information reported in this post.

    0000085
    968 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Ocelot WebSocket upgrade bypasses IP allow/block controls (CVE-2026-58172) Ocelot through 24.1.0 has a security control bypass in its WebSocket upgrade handling that allows blocked clients to slip past configured IP-based allow/block restrictions. The root cause is a pipeline misconfiguration/logic flaw: a MapWhen branch in OcelotPipelineExtensions.cs for WebSocket upgrades omits SecurityMiddleware, resulting in inconsistent enforcement. An attacker exploits this by sending a WebSocket Upgrade request so their traffic is routed through the branch that skips the IP restriction checks, requiring only network access to the gateway. If exploited, blocked sources can reach and proxy to downstream services, enabling unauthorized access and potential data exposure or follow-on compromise depending on what those services expose. 👉 Affected: Ocelot <= 24.1.0 | Upgrade to version containing commit f156fd4

    Post summary

    The notice announces a critical WebSocket upgrade bypass in Ocelot (CVE‑2026‑58172), explains the technical flaw, and advises upgrading to a patched commit.

    00000100
    232 followersView on X

Explore more