Junglewise Threat Intelligence

CVE-2026-75885: OpenShift console SSRF and resource exhaustion in devfile endpoints

CVE-2026-75885 · Severity: critical · CVSS 9.3 · Published 2026-09-18

Technologies: Red Hat OpenShift Container Platform. Vendors: Red Hat.

Executive brief

OpenShift Container Platform's web console exposes API endpoints for parsing devfile configurations without authentication. An attacker can exploit this to make the console perform requests to internal cluster services (revealing sensitive data) or send large payloads that exhaust memory, taking the console offline and disrupting cluster operations.

Technical details

The `/api/devfile/` and `/api/devfile/samples/` endpoints lack authentication and accept crafted devfile payloads. Attackers can leverage this via Server-Side Request Forgery (CWE-918) to scan or access internal services, or trigger unbounded memory allocation through large requests without content-length headers, causing denial of service in the console pod.

Affected products

  • Red Hat OpenShift Container Platform

Timeline

  • 2026-09-18: disclosed

References

Related threats