High severity7.4NVD Advisory· Published Aug 11, 2026· Updated Sep 21, 2026
CVE-2026-50236
CVE-2026-50236
Description
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
11- access.redhat.com/errata/RHSA-2026:54545nvd
- access.redhat.com/errata/RHSA-2026:54555nvd
- access.redhat.com/errata/RHSA-2026:54583nvd
- access.redhat.com/errata/RHSA-2026:54602nvd
- access.redhat.com/errata/RHSA-2026:54770nvd
- access.redhat.com/errata/RHSA-2026:56789nvd
- access.redhat.com/errata/RHSA-2026:56854nvd
- access.redhat.com/errata/RHSA-2026:56912nvd
- access.redhat.com/errata/RHSA-2026:60023nvd
- access.redhat.com/security/cve/CVE-2026-50236nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.