External risk intelligence

OpenShift Console SSRF and DoS Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-75885

The vulnerability affects the OpenShift console, which is a web-based management interface. In many enterprise deployments, these console endpoints are exposed to facilitate administrative access or developer workflows, making them a common target reachable from network perimeters.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the OpenShift console allows unauthenticated remote attackers to exploit certain endpoints, potentially leading to server-side request forgery and denial of service through memory exhaustion. This matters because it impacts a core management interface and could expose internal systems or disrupt operations. The main concern is confirming relevance and exposure to your specific OpenShift deployments.

  • Attackers can access sensitive console functions remotely.
  • It affects a critical management interface for developers.
  • Confirm if your OpenShift console is exposed externally.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach the OpenShift console and send specially crafted requests to specific API endpoints. By exploiting this, an attacker could trick the console into making requests to internal services or cause memory exhaustion, leading to potential data exposure and service disruption.

  • Accessible via the network without authentication.
  • Triggers by sending crafted devfile payloads.
  • Risks server-side request forgery and denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the OpenShift console could expose sensitive information about internal services to unauthenticated attackers and disrupt service availability. When supported, crafted devfile payloads sent to specific API endpoints may cause the console to make requests to internal resources, reflecting partial responses back to the attacker. Repeated large requests, when unsupported by a content length, can also lead to service denial.

  • Internal service details could be exposed.
  • Crafted requests can trigger internal calls.
  • Service disruption and information leakage.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OpenShift console's SSRF and DoS vulnerabilities require immediate attention from platform and security teams. The first practical step is to identify all instances of the OpenShift console, assess their network reachability and criticality, and locate the accountable owners for remediation planning.

  • Platform and security teams should own this.
  • Verify console exposure and critical assets.
  • Plan remediation based on business impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the OpenShift console?

The OpenShift console is a web-based user interface used to manage containerized applications and infrastructure within an OpenShift cluster. It provides developers and administrators with a centralized dashboard for deploying, monitoring, and scaling workloads across their environments.

What does CVE-2026-75885 mean for security?

This CVE involves Server-Side Request Forgery (SSRF), a weakness categorized as CWE-918. It means an attacker can trick the console into acting as a proxy, forcing it to send unauthorized requests to internal services that are typically hidden from the public network. It also allows for memory exhaustion that can crash the service.

How is this vulnerability triggered?

An attacker triggers this by sending specially crafted devfile payloads to specific API endpoints within the console without needing authentication. Simply browsing the console or viewing legitimate resources does not trigger the vulnerability; it requires the submission of these malicious, unauthorized payloads.

Is my deployment at risk from CVE-2026-75885?

Halo Surface Signal indicates that because the OpenShift console is often intentionally exposed to facilitate administrative access or developer workflows, it is frequently reachable from network perimeters. You should consider your deployment at higher risk if your console is accessible over the internet or broad internal networks.

Do I need to take action if I run OpenShift?

Yes. Start by identifying all instances of the OpenShift console within your environment and mapping their network reachability. Coordinate with your platform and security teams to prioritize the most critical assets and prepare for the necessary updates provided by the vendor.

References