{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-BFAD196C",
  "slug": "cve-2026-75885-openshift-console-unauth-devfile-ssrf",
  "title": "OpenShift console unauth Devfile SSRF and DoS",
  "aliases": [
    "CVE-2026-75885",
    "OpenShift console Devfile SSRF"
  ],
  "summary": "Unauthenticated callers can hit OpenShift console `/api/devfile/` and `/api/devfile/samples/` with crafted Devfile payloads, driving SSRF toward internal services and unbounded memory growth for DoS. Red Hat rates this Important (CVSS 9.3 class). Apply the RHSA / patched console build for your OpenShift train.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Exact fixed console image tags vary by OpenShift minor; confirm against the Red Hat CVE page / RHSA for your cluster channel. RHSA may lag the CVE disclosure.",
  "firstObservedAt": "2026-09-18T22:10:33.132Z",
  "lastObservedAt": "2026-09-18T22:51:30.827Z",
  "publishedAt": "2026-09-20T13:02:24.121Z",
  "reviewedAt": "2026-09-20T13:02:08.261Z",
  "expiresAt": "2026-09-18T22:51:30.827Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "rh-cve-75885",
      "label": "Red Hat CVE-2026-75885",
      "url": "https://access.redhat.com/security/cve/CVE-2026-75885",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-18T00:00:00.000Z"
    },
    {
      "id": "bugzilla-2517885",
      "label": "Red Hat Bugzilla 2517885",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517885",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-18T22:51:30.827Z"
    },
    {
      "id": "hol-blog-75885",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-75885-openshift-console-unauth-devfile-ssrf",
      "sourceType": "other_primary",
      "observedAt": "2026-09-18T22:51:30.827Z"
    }
  ],
  "artifacts": [
    {
      "id": "openshift-console",
      "artifactClass": "package",
      "ecosystem": "openshift",
      "name": "openshift/console",
      "version": "vulnerable until RHSA for your train",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-18T22:10:33.132Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-75885 disclosed: unauthenticated SSRF and resource exhaustion via OpenShift console Devfile parser endpoints.",
      "sourceIds": [
        "rh-cve-75885",
        "bugzilla-2517885"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-18T22:51:30.827Z",
      "eventType": "other",
      "summary": "HOL Guard published BREAKING operator coverage and company social for CVE-2026-75885.",
      "sourceIds": [
        "hol-blog-75885"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "RHSA image tags are train-specific — use the Red Hat advisory for your OpenShift minor.",
    "Network policies and an authenticated-only console reduce exposure but do not replace the patch.",
    "This campaign covers console Devfile SSRF/DoS, not unrelated OpenShift control-plane CVEs."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-75885-openshift-console-unauth-devfile-ssrf/corrections"
}
