Bug 2517886 (CVE-2026-75886) - CVE-2026-75886 openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding
Summary: CVE-2026-75886 openshift/console: openshift/console: Unauthenticated reverse ...
Keywords:
Status: NEW
Alias: CVE-2026-75886
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-18 13:11 UTC by OSIDB Bzimport
Modified: 2026-09-23 20:12 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-18 13:11:32 UTC
The CatalogdHandler() in the OpenShift console is registered without authHandler (pkg/server/server.go:340). Furthermore, the CatalogdProxyConfig is the only proxy config that omits HeaderBlacklist: srv.ProxyHeaderDenyList (cmd/bridge/main.go:429-432), so the user's openshift-session-token cookie is forwarded verbatim to the catalogd service.

Any unauthenticated network actor can GET /api/catalogd/<arbitrary-path> and the console pod will issue a TLS request to catalogd-service.openshift-catalogd.svc:443/<arbitrary-path>. This discloses the full operator-catalog index (intended to be cluster-internal) and provides a relay primitive into the openshift-catalogd namespace.

Tested and reproduced on OCP 5.0 nightly cluster.

Upstream: https://github.com/openshift/console
File: pkg/server/server.go:340, pkg/server/server.go:859-868, cmd/bridge/main.go:429-432


Note You need to log in before you can comment on or make changes to this bug.