Skip to finding
important · Edge — OpenShift

Unauthenticated OpenShift console requests can proxy into cluster-internal services.

Affects

Red Hat OpenShift Container Platform console, the web management interface deployed with OpenShift Kubernetes clusters.

A caller reaching the public devfile endpoints can make the console pod request an attacker-selected internal URL and receive part of its response.

Detail and 2 sources

The same parser can exhaust console memory with requests lacking a declared content length, and the accessible record does not identify exact fixed builds.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026