A flaw was found in the OpenShift console....
Critical severity
Unreviewed
Published
Sep 19, 2026
to the GitHub Advisory Database
•
Updated Oct 1, 2026
Description
Published by the National Vulnerability Database
Sep 18, 2026
Published to the GitHub Advisory Database
Sep 19, 2026
Last updated
Oct 1, 2026
A flaw was found in the OpenShift console. Unauthenticated access to the
/api/devfile/and/api/devfile/samples/endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).References