VDB
CVE-2026-75885
CVE-2026-75885
PUBLISHED
CVSS 9.3 CRITICAL
Reported by redhat · Published September 18, 2026
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).
Risk Scores
CVSS 3.1
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1790102793 |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905, 1790130905, 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1790102793 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788, 1790142788, 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153, 1790112153, 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950, 1790095950 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
Timeline
- Sep 18, 2026 CVE Published
- Sep 19, 2026 EPSS Score
- Sep 19, 2026 Coalition ESS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
References
- RHSA-2026:70587 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:70617 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:70647 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71447 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71450 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71453 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71454 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2517885 issue-trackingx_refsource_REDHAT