
🚨 CRITICAL: CVE-2026-58172 (CVSS 9.1) - Ocelot API Gateway ≤24.1.0 allows IP blocklist bypass via WebSocket upgrade requests. SecurityMiddleware omitted in WebSocket pipeline. Patch: commit f156fd4. #CVE #PatchNow #ThreatIntel https://t.co/nmZ1DZJGfr
Post summary
The tweet highlights the critical CVE‑2026‑58172 in Ocelot API Gateway, details the IP blocklist bypass vulnerability, and directs users to a specific patch commit to remediate the flaw.


