{"type":"bundle","id":"bundle--1af1a7d3-4a99-5e93-bd38-072e0b29533c","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--cb5f2056-0638-5458-8412-5ecbf9842173","created":"2026-09-20T13:02:24.121Z","modified":"2026-09-20T13:02:08.261Z","name":"OpenShift console unauth Devfile SSRF and DoS","description":"Unauthenticated callers can hit OpenShift console `/api/devfile/` and `/api/devfile/samples/` with crafted Devfile payloads, driving SSRF toward internal services and unbounded memory growth for DoS. Red Hat rates this Important (CVSS 9.3 class). Apply the RHSA / patched console build for your OpenShift train.","aliases":["CVE-2026-75885","OpenShift console Devfile SSRF"],"first_seen":"2026-09-18T22:10:33.132Z","last_seen":"2026-09-18T22:51:30.827Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Red Hat CVE-2026-75885","url":"https://access.redhat.com/security/cve/CVE-2026-75885"},{"source_name":"Red Hat Bugzilla 2517885","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517885"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-75885-openshift-console-unauth-devfile-ssrf"}]}]}