Executive brief
OpenShift Container Platform's web console exposes API endpoints for parsing devfile configurations without authentication. An attacker can exploit this to make the console perform requests to internal cluster services (revealing sensitive data) or send large payloads that exhaust memory, taking the console offline and disrupting cluster operations.
Technical details
The `/api/devfile/` and `/api/devfile/samples/` endpoints lack authentication and accept crafted devfile payloads. Attackers can leverage this via Server-Side Request Forgery (CWE-918) to scan or access internal services, or trigger unbounded memory allocation through large requests without content-length headers, causing denial of service in the console pod.
Affected products
- Red Hat OpenShift Container Platform
Timeline
- 2026-09-18: disclosed