A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 30 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat cost Management Metrics Operator |
|
| Vendors & Products |
Red Hat
Red Hat cost Management Metrics Operator |
Thu, 30 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token. | |
| Title | Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy) | |
| First Time appeared |
Redhat
Redhat cost Management |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:cost_management:4 | |
| Vendors & Products |
Redhat
Redhat cost Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-30T12:00:27.382Z
Reserved: 2026-07-30T11:01:08.520Z
Link: CVE-2026-18378
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T15:28:58Z
Weaknesses