What is CVE-2026-50237?
A critical Server-Side Request Forgery (SSRF) and supply chain vulnerability was discovered in the OpenShift Console Helm catalog proxy. An attacker can exploit this by creating a 'ProjectHelmChartRepository' with a malicious URL, forcing the console pod to make server-side requests to arbitrary destinations, bypassing egress restrictions. Users should immediately update their OpenShift Console to the latest patched version.
Azərbaycanca: Bu kritik zəiflik OpenShift Console-un Helm kataloq proksisində aşkarlanıb. Təcavüzkar 'namespace' səviyyəsində xüsusi hazırlanmış 'ProjectHelmChartRepository' obyekti yaradaraq server tərəfindən istənilən URL-ə sorğu göndərə bilir ki, bu da Server-Side Request Forgery (SSRF) hücumuna və təchizat zəncirinə müdaxiləyə səbəb olur. İstifadəçilərə dərhal OpenShift Console-u ən son patched versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What component of OpenShift Console is affected by CVE-2026-50237?
This critical vulnerability was discovered in the Helm catalog proxy of OpenShift Console.
How can an attacker exploit CVE-2026-50237?
An attacker can exploit this by creating a 'ProjectHelmChartRepository' with a malicious URL, forcing the console pod to make server-side requests to arbitrary destinations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.