A Server-Side Request Forgery and supply chain flaw was...
High severity
Unreviewed
Published
Aug 11, 2026
to the GitHub Advisory Database
•
Updated Aug 20, 2026
Description
Published by the National Vulnerability Database
Aug 11, 2026
Published to the GitHub Advisory Database
Aug 11, 2026
Last updated
Aug 20, 2026
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
References