GHSA-5mvj-m7fw-m49wHighCVSS 7.4

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm...

Published
August 11, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (1)

📋 Description

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.

🔗 References (11)