← Back to search

CVE-2026-75885

9.3 CRITICAL

Published 2026-09-18 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows unauthenticated access to internal services via crafted devfile payloads, leading to SSRF and potential DoS.
Exploitability
Exploitation requires unauthenticated access to specific API endpoints and crafting of devfile payloads, making it moderately difficult.
Blast radius
If exploited, the impact could be significant, as it allows access to internal services and could lead to a DoS condition.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable access to the `/api/devfile/` and `/api/devfile/samples/` endpoints or restrict access to authenticated users only.
ssrfdosapiunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Weaknesses

CWE-918

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.