What is CVE-2026-50236?
An authenticated SSRF flaw in OpenShift Console Dev Console webhook helpers allows server-side fetching of user-supplied URLs without validation, enabling targeted requests to arbitrary endpoints from the console pod's privileged network position. Mitigation requires strict validation and path neutralization to prevent full response reflection.
Azərbaycanca: Bu autentifikasiya olunmuş SSRF (Server-Side Request Forgery) zəifliyi OpenShift Console Dev Console webhook köməkçilərində aşkar edilib. Təsdiqlənmiş istifadəçi tərəfindən verilən URL-lər server tərəfindən yoxlanılmadan emal edilir ki, bu da konsol pod-un imtiyazlı şəbəkəsindən ixtiyari endpoint-lərə sorğu göndərməyə imkan yaradır. Bu problemi aradan qaldırmaq üçün daxil olan URL-lərdə ciddi validasiya və path neytrallaşdırma tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which platform is affected by CVE-2026-50236?
This authenticated SSRF vulnerability was found in OpenShift Console's Dev Console webhook helpers.
What can an attacker achieve by exploiting CVE-2026-50236?
Since user-supplied URLs are processed without validation, it enables sending requests to arbitrary endpoints from the console pod's privileged network position.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.