Security Advisory

CVE-2026-50236

7.4
HIGH

Vulnerability Description

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Published Date August 11, 2026
Official Source NIST NVD Advisory