7.5

CVE-2026-49329

Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.19
Default Statusaffected
Version 1790611633
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.20
Default Statusaffected
Version 1790702087
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.21
Default Statusaffected
Version 1790707106
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4.22
Default Statusaffected
Version 1790713150
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.36
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-407 Inefficient Algorithmic Complexity

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

https://access.redhat.com/security/cve/CVE-2026-49329
https://bugzilla.redhat.com/show_bug.cgi?id=2483248
https://access.redhat.com/errata/RHSA-2026:74383
https://access.redhat.com/errata/RHSA-2026:74429
https://access.redhat.com/errata/RHSA-2026:74380
https://access.redhat.com/errata/RHSA-2026:74434