Red HatCVE-2026-50236
Red Hat OpenShift Console: server-side request forgery
High7.4CVE-2026-50236 · Published Aug 11, 2026 · updated Sep 21, 2026
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
- www.cve.org/CVERecord?id=CVE-2026-50236
- nvd.nist.gov/vuln/detail/CVE-2026-50236
- access.redhat.com/errata/RHSA-2026:54545
- access.redhat.com/errata/RHSA-2026:54555
- access.redhat.com/errata/RHSA-2026:54583
- access.redhat.com/errata/RHSA-2026:54602
- access.redhat.com/errata/RHSA-2026:54770
- access.redhat.com/errata/RHSA-2026:56789
- access.redhat.com/errata/RHSA-2026:56854
- access.redhat.com/errata/RHSA-2026:56912
- access.redhat.com/errata/RHSA-2026:60023
- access.redhat.com/security/cve/CVE-2026-50236
- bugzilla.redhat.com/show_bug.cgi?id=2484745
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Red Hat FreeIPA: improper authorization | High8.2 | No fix yet |
| Aug 11 | Red Hat search-v2-api. The authentication middleware: authentication bypass | High7.5 | No fix yet |
| Aug 11 | Red Hat acm-search-v2-api-rhel9.: information disclosure | Medium5.3 | No fix yet |
| Aug 11 | Red Hat insights-client.: information disclosure | High7.1 | No fix yet |
| Aug 11 | Red Hat insights-client. A compromised managed cluster: information disclosure | Medium6.8 | No fix yet |
| Aug 11 | Red Hat insights-client: secrets in logs | Medium6.3 | No fix yet |