Information Disclosure Vulnerability in Red Hat Insights Client
CVE-2026-71474
6.3MEDIUM
What is CVE-2026-71474?
An information disclosure vulnerability exists within the Red Hat Insights Client when it encounters a non-200 HTTP response. The application logs the request headers, which may unintentionally include sensitive information such as the pull-secret token from cloud.openshift.com. If a local user gains access to the pod logs on the hub, they can potentially read this long-lived credential, leading to unauthorized access to Red Hat cloud services. It is essential for users and administrators to be aware of this vulnerability and to ensure that proper security measures are in place to mitigate any risks.