Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS). | |
| Title | Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T21:58:11.958Z
Reserved: 2026-08-18T13:44:59.078Z
Link: CVE-2026-75885
No data.
Status : Received
Published: 2026-09-18T22:17:10.313
Modified: 2026-09-18T22:17:10.313
Link: CVE-2026-75885
OpenCVE Enrichment
No data.
-
CWE-918
Server-Side Request Forgery (SSRF)