Skip to content
Red HatCVE-2026-18381

Red Hat Cost Management Metrics Operator: server-side request forgery

High7.6CVE-2026-18381 · Published Jul 30, 2026 · updated Aug 12, 2026

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Cost Management Metrics Operator
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Red Hat advisories

All Red Hat
Advisory
ansible-collection-redhat-leapp: information disclosure
Medium6.2Jul 30
ansible-collection-redhat-leapp.: insecure permissions
Medium5.5Jul 30
Red Hat Samba: out-of-bounds read
Medium5.3Jul 30
Red Hat Enterprise Linux 10: improper authorization
High8.8Jul 30
Red Hat Samba: denial of service
Medium5.3Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.