Description
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.
Problem types
Server-Side Request Forgery (SSRF)
Product status
Timeline
| 2025-12-10: | Reported to Red Hat. |
| 2025-12-10: | Made public. |
Credits
Red Hat would like to thank Alessandro Affinito for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-14443
bugzilla.redhat.com/show_bug.cgi?id=2420964 (RHBZ#2420964)
github.com/tuxerrante/openshift-ssrf
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.