Red Hat OpenShift Container Platform 4.14 vulnerability

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.

Published 11 Aug 2026Updated 5 Sep 202611 sources
CVSS 7.4

Source timeline

CVE record published by NVDView source ↗