Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18378— Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy)

CVSS 7.6 · High EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProductVersion RangeStatus
Red HatCost Management Metrics Operatoranyaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18378

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy)
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
koku-metrics-operator 服务端请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Koku koku-metrics-operator是Koku团队开源的一个基于 Golang 编写的 OpenShift Operator。 koku-metrics-operator存在服务端请求伪造漏洞,该漏洞源于允许用户编辑CostManagementMetricsConfig自定义资源指定任意上传URL,当认证类型设置为token时,集群全局的Red Hat Cloud pull-secret bearer token会附加到HTTP请求中,导致攻击者获取该token。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatCost Management Metrics Operator-cpe:/a:redhat:cost_management:4

II. Public POCs for CVE-2026-18378

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18378

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18378 (2)

Same Patch Batch · Red Hat · 2026-07-30 · 15 CVEs total

CVE-2026-165268.8 HIGHPcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
CVE-2026-582228.8 HIGHSamba: samba ad ldap compare filter injection and trusted-request confusion disclose prote
CVE-2026-165247.8 HIGHPcp: pcp linux_sockets pmda: arbitrary command execution via command injection
CVE-2026-183817.6 HIGHProject-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token
CVE-2026-165297.5 HIGHPcp: pcp: denial of service due to signed integer overflow
CVE-2026-165277.3 HIGHPcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access r
CVE-2026-183826.8 MEDIUMProject-koku/koku-metrics-operator: koku-metrics-operator: service-account client credenti
CVE-2026-165306.5 MEDIUMPcp: pcp: remote denial of service and information leakage
CVE-2026-685626.2 MEDIUMAnsible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure v
CVE-2026-183695.8 MEDIUMDogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identif
CVE-2026-685635.5 MEDIUMAnsible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure o
CVE-2026-165315.3 MEDIUMPcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet
CVE-2026-582185.3 MEDIUMSamba: dns signing dos via tkey name cache exhaustion
CVE-2026-582165.3 MEDIUMSamba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the serve

IV. Related Vulnerabilities

V. Comments for CVE-2026-18378

No comments yet


Leave a comment