Security Advisory

CVE-2026-50236

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 11:23:59
Last updated 2026-08-23 10:58:40
Assigner redhat
CVSS score 7.4
State PUBLISHED

Description

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.