openshift4/ose-console vulnerabilities
CVEs whose affected-version data names the openshift4/ose-console package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-75885Critical· 9.3A flaw was found in the OpenShift console
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF)…
CVE-2026-50237High· 7.4A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassin…
CVE-2026-50236High· 7.4An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full resp…