Input Validation Flaw in OAuth Server of OpenShift by Red Hat
CVE-2026-49329

7.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
1 September 2026

What is CVE-2026-49329?

A vulnerability has been identified in the OpenShift OAuth Server that allows unauthorized attackers to exploit the Accept-Language header without proper input validation. The flaw occurs as the OAuth login and error page endpoints fail to adequately sanitize this header before processing it. An attacker can craft the Accept-Language header using '_' separators, leading to a bypass of previous mitigations. Consequently, this can result in excessive CPU usage through quadratic-time parsing, effectively denying authentication services to all users within the affected cluster.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank tonghuaroot for reporting this issue.
.