HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-50236 — An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhoo...
·Source: NIST NVD
Updated:
Executive Summary
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Analysis
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position. CVSS Score: 7.4. Published: 2026-08-11T12:17:38.183.