{
  "threat_severity" : "Important",
  "public_date" : "2026-08-11T09:36:00Z",
  "bugzilla" : {
    "description" : "openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console",
    "id" : "2484745",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2484745"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.", "An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position." ],
  "acknowledgement" : "Red Hat would like to thank Arpit Jain (GitHub handle: arpitjain099) and Christopher Lusk (North Echo Security Research) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:56789",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "openshift4/ose-console:1787056403"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:56912",
    "cpe" : "cpe:/a:redhat:openshift:4.15::el9",
    "package" : "openshift4/ose-console:1787028559"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.16",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:56854",
    "cpe" : "cpe:/a:redhat:openshift:4.16::el9",
    "package" : "openshift4/ose-console-rhel9:1787054159"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.17",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:60023",
    "cpe" : "cpe:/a:redhat:openshift:4.17::el9",
    "package" : "openshift4/ose-console-rhel9:1787631382"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.18",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:54545",
    "cpe" : "cpe:/a:redhat:openshift:4.18::el9",
    "package" : "openshift4/ose-console-rhel9:1786540776"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.19",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:54555",
    "cpe" : "cpe:/a:redhat:openshift:4.19::el9",
    "package" : "openshift4/ose-console-rhel9:1786486822"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.20",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:54583",
    "cpe" : "cpe:/a:redhat:openshift:4.20::el9",
    "package" : "openshift4/ose-console-rhel9:1786534931"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.21",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:54602",
    "cpe" : "cpe:/a:redhat:openshift:4.21::el9",
    "package" : "openshift4/ose-console-rhel9:1786574043"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.22",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:54770",
    "cpe" : "cpe:/a:redhat:openshift:4.22::el9",
    "package" : "openshift4/ose-console-rhel9:1786607915"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-50236\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50236" ],
  "name" : "CVE-2026-50236",
  "mitigation" : {
    "value" : "Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators.",
    "lang" : "en:us"
  },
  "csaw" : false
}