<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:43:35 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-50236 — Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook hel…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-50236</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.20, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Container Platform 4.22&lt;/p&gt;
&lt;p&gt;An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod&amp;#39;s privileged network position.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.20, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Container Platform 4.22&lt;/p&gt;
&lt;p&gt;An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod&amp;#39;s privileged network position.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-50236</guid>
    </item>
  </channel>
</rss>
