CVE-2026-75885: Red Hat Openshift Container Platform 4.12
Critical severity, CVSS 9.3. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).
Affected products
- Red Hat Red Hat Openshift Container Platform 4.12: before 1790102793 (fixed in 1790102793)
- Red Hat Red Hat Openshift Container Platform 4.14: before 1790606051 (fixed in 1790606051)
- Red Hat Red Hat Openshift Container Platform 4.16: before 1790636171 (fixed in 1790636171)
- Red Hat Red Hat Openshift Container Platform 4.17: before 1789939565 (fixed in 1789939565)
- Red Hat Red Hat Openshift Container Platform 4.18: before 1789904865 (fixed in 1789904865)
- Red Hat Red Hat Openshift Container Platform 4.19: before 1790095950 (fixed in 1790095950)
- Red Hat Red Hat Openshift Container Platform 4.20: before 1790112153 (fixed in 1790112153)
- Red Hat Red Hat Openshift Container Platform 4.21: before 1790142788 (fixed in 1790142788)
- Red Hat Red Hat Openshift Container Platform 4.22: before 1790130905 (fixed in 1790130905)
Published 2026-09-18. Last modified 2026-10-08.