VDB
CVE-2026-50236
CVE-2026-50236
PUBLISHED
CVSS 7.4 HIGH
Reported by redhat · Published August 11, 2026
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Risk Scores
CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1787056403 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787028559 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1787054159 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1786540776 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786486822 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786534931 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786574043 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786607915 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1787054159 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787028559 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1786540776, 1786540776, 1786540776 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786574043, 1786574043, 1786574043 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786486822, 1786486822, 1786486822 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786534931, 1786534931, 1786534931 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1787056403 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.2 | 1786534931, 1786534931 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786607915, 1786607915, 1786607915 |
Timeline
- Aug 11, 2026 CVE Published
- Aug 12, 2026 Coalition ESS Score
- Aug 19, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Security Advisory
- Aug 27, 2026 Security Advisory
- Aug 27, 2026 Security Advisory
References
- RHSA-2026:54545 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54555 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54583 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54602 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54770 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56789 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56854 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56912 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2484745 issue-trackingx_refsource_REDHAT