← back
CVE-2026-50236highCWE-918

Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.4epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L