Server-Side Request Forgery Vulnerability in OpenShift Console by Red Hat
CVE-2026-50236

7.4HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-50236?

An authenticated server-side request forgery (SSRF) vulnerability exists in the webhook helpers of the OpenShift Console Dev Console. This flaw arises because user-provided URLs can be fetched server-side without proper validation. Consequently, this lack of validation permits potential attackers to target arbitrary endpoints and to reflect full responses from the console pod's privileged network. The risk is that an attacker could exploit this SSRF flaw to interact with internal services, leading to unauthorized data access and potential further exploitation within the network.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
.