CVE-2025-14443
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential Denial of Service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-14443, https://github.com/openshift/openshift-apiserver/pull/591, https://github.com/openshift/openshift-apiserver/pull/599, https://access.redhat.com/security/cve/CVE-2025-14443, https://bugzilla.redhat.com/show_bug.cgi?id=2420964, https://github.com/openshift/openshift-apiserver
