Executive brief
The OpenShift Console contains a server-side request forgery vulnerability in its Helm catalog proxy component. A namespace tenant can exploit this to make the console pod fetch arbitrary URLs, bypassing network restrictions. When combined with catalog poisoning techniques, this enables attackers to escalate privileges to administrator level.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the OpenShift Console's Helm catalog proxy. A tenant with namespace access can create a ProjectHelmChartRepository resource pointing to an arbitrary URL, which the console pod will fetch server-side, circumventing normal egress restrictions. The attack requires catalog metadata poisoning and admin-mediated chart installation to achieve privilege escalation. This is a multi-step attack leveraging supply chain mechanics to escalate from tenant to admin privileges. Fixes are available in OpenShift Container Platform 4.13.70 and later.
Affected products
- Red Hat OpenShift Container Platform 4.13 prior to 4.13.70
Timeline
- 2026-08-11: disclosed
- 2026-08-20: patched: Red Hat OpenShift Container Platform 4.13.70