GHSA-c4v8-c9cj-xrmrHighCVSS 7.4
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User...
🔗 CVE IDs covered (1)
📋 Description
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-50236
- https://access.redhat.com/security/cve/CVE-2026-50236
- https://bugzilla.redhat.com/show_bug.cgi?id=2484745
- https://access.redhat.com/errata/RHSA-2026:54583
- https://access.redhat.com/errata/RHSA-2026:54602
- https://access.redhat.com/errata/RHSA-2026:54770
- https://access.redhat.com/errata/RHSA-2026:54555
- https://access.redhat.com/errata/RHSA-2026:54545
- https://github.com/advisories/GHSA-c4v8-c9cj-xrmr