cvedb.io
CVE-2026-71474
MEDIUM · CVSS 6.3
EPSS exploitation probability: 0%
Published 2026-08-11T20:18:45.547 · Last modified 2026-08-11T20:18:45.547

Summary

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.