๐Ÿ” CVE Alert

CVE-2026-50236

HIGH 7.4

Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.

CWE CWE-918
Vendor red hat
Product red hat openshift container platform 4.14
Published Aug 11, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat openshift container platform 4.14

Be the first to know when new high vulnerabilities affecting red hat red hat openshift container platform 4.14 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.19
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.20
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.21
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.22
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:54545 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:54555 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:54583 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:54602 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:54770 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:56789 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:56854 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:56912 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:60023 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-50236 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2484745

Credits

Red Hat would like to thank Arpit Jain (GitHub handle: arpitjain099) and Christopher Lusk (North Echo Security Research) for reporting this issue.