Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected products
Red Hat · Red Hat OpenShift Container Platform 4.14Red Hat · Red Hat OpenShift Container Platform 4.15Red Hat · Red Hat OpenShift Container Platform 4.16Red Hat · Red Hat OpenShift Container Platform 4.17Red Hat · Red Hat OpenShift Container Platform 4.18Red Hat · Red Hat OpenShift Container Platform 4.19Red Hat · Red Hat OpenShift Container Platform 4.20Red Hat · Red Hat OpenShift Container Platform 4.21Red Hat · Red Hat OpenShift Container Platform 4.22References
https://access.redhat.com/errata/RHSA-2026:54545https://access.redhat.com/errata/RHSA-2026:54555https://access.redhat.com/errata/RHSA-2026:54583https://access.redhat.com/errata/RHSA-2026:54602https://access.redhat.com/errata/RHSA-2026:54770https://access.redhat.com/errata/RHSA-2026:56789https://access.redhat.com/errata/RHSA-2026:56854https://access.redhat.com/errata/RHSA-2026:56912https://access.redhat.com/errata/RHSA-2026:60023https://access.redhat.com/security/cve/CVE-2026-50236https://bugzilla.redhat.com/show_bug.cgi?id=2484745