OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-75885 (CVSS 9.3)

NVD · officialPublished Sep 18, 2026Risk 50/100EPSS 0.4%

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:NoneA:Low

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source