Description
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).
Published: 2026-09-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote SSRF & Denial of Service
Action: Check Patch
AI Analysis

Impact

A flaw in the OpenShift console allows unauthenticated callers to POST to the /api/devfile and /api/devfile/samples endpoints. By sending crafted devfile payloads, an attacker can cause the console pod to perform arbitrary outbound HTTP requests, enabling Server‑Side Request Forgery that exposes internal services and partial responses. Repeated large payloads without a content‑length header lead to unbounded memory growth, potentially exhausting the console container’s resources and resulting in a denial of service.

Affected Systems

Affected product is Red Hat OpenShift Container Platform 4. The CVE does not provide specific version details, so it is unclear which releases are impacted; any installation that includes the OpenShift console could be vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity flaw. The EPSS score of 0.00414 (less than 1%) indicates a very low but nonzero exploitation probability; combined with the lack of authentication and common HTTP endpoints the attack has a non‑negligible chance of success. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly disclosed exploits are known. An attacker only needs network access to the cluster’s console pod, making the attack path straightforward. Exploitation proceeds by sending a crafted devfile payload via HTTP to the exposed endpoint, triggering either an internal SSRF or an unbounded memory allocation that brings the console pod down.

Generated by OpenCVE AI on September 19, 2026 at 14:51 UTC.

Remediation

Vendor Workaround

https://access.redhat.com/solutions/7148487


OpenCVE Recommended Actions

  • Apply any available Red Hat update that addresses the SSRF and memory exhaustion flaw in the OpenShift Console.
  • Deploy network policies or firewall rules to restrict unauthenticated access to the /api/devfile and /api/devfile/samples endpoints, allowing only internal or trusted sources.
  • Configure admission controllers or request size limits to reject devfile requests that lack a Content‑Length header or exceed a safe size threshold, thereby mitigating potential DoS attacks.
  • Refer to the Red Hat advisory for workaround instructions; note that the available workaround may not meet deployment or stability criteria and could provide limited protection.

Generated by OpenCVE AI on September 19, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el9
cpe:/a:redhat:openshift:4.16::el9
References

Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift:4.12::el9
cpe:/a:redhat:openshift:4.17::el9
cpe:/a:redhat:openshift:4.18::el9
References

Wed, 30 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.19::el9
References

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.20::el9
cpe:/a:redhat:openshift:4.21::el9
cpe:/a:redhat:openshift:4.22::el9
References

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Vendors & Products Redhat openshift Container Platform

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).
Title Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint
First Time appeared Redhat
Redhat openshift
Weaknesses CWE-918
CPEs cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat openshift
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Redhat Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-09T07:19:04.873Z

Reserved: 2026-08-18T13:44:59.078Z

Link: CVE-2026-75885

cve-icon Vulnrichment

Updated: 2026-09-21T19:48:47.574Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T22:17:10.313

Modified: 2026-10-08T15:17:54.840

Link: CVE-2026-75885

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T13:48:11Z

Links: CVE-2026-75885 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)