VDB
CVE-2026-50237
CVE-2026-50237
PUBLISHED
CVSS 7.4 HIGH
Reported by redhat · Published August 11, 2026
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
Risk Scores
CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786511587 |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477760 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1787056403 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 1787028559 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1787054159 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1786540776 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786486822 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786534931 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1786574043 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786607915 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1786607915, 1786607915, 1786607915 |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 1786477760, 1786477760, 1786477760 |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1786511587, 1786511587, 1786511587 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 1787054159 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1786534931, 1786534931, 1786534931 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 1787056403 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1786540776, 1786540776, 1786540776 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1786486822, 1786486822, 1786486822 |
…and 3 more
Timeline
- Aug 11, 2026 CVE Published
- Aug 12, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Distribution Patch
- Aug 27, 2026 Security Advisory
References
- RHSA-2026:54188 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54206 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54545 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54555 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54583 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54602 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:54770 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56789 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56854 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:56912 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2484746 issue-trackingx_refsource_REDHAT