A flaw was found in insights-client. (CVE-2026-71474)
A vulnerability in insights-client causes it to log sensitive pull-secret tokens in pod logs when receiving non-200 HTTP responses at high verbosity levels. This can expose long-lived cloud.openshift.com credentials to local users with pod log access, potentially allowing unauthorized access to Red Hat cloud services. The flaw is rated medium severity with a CVSS score of 6.3. No official patch or mitigation currently meets Red Hat's criteria for deployment and ease of use.
AI Analysis
Technical Summary
The insights-client application logs request headers, including the cloud.openshift.com pull-secret token, when it receives a non-200 response and logging verbosity is set to 3 or higher. This token is written to stderr and pod logs on the hub, making it accessible to any local user who has permission to read pod logs. This information disclosure vulnerability (CWE-532) could allow unauthorized access to Red Hat cloud services. The vulnerability has a CVSS 3.1 base score of 6.3 (medium severity) with network attack vector, high attack complexity, low privileges required, no user interaction, and a confidentiality impact only. Red Hat has not released an official fix or mitigation that meets their criteria for broad deployment.
Potential Impact
Exposure of the cloud.openshift.com pull-secret token in pod logs can lead to unauthorized access to Red Hat cloud services by local users with pod log access. The impact is limited by the need for specific logging conditions (verbosity level 3 or higher) and existing permissions to access pod logs. There is no impact on integrity or availability.
Mitigation Recommendations
Currently, no official fix or mitigation is available that meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should be aware of the risk when enabling high verbosity logging levels and restrict pod log access to trusted users only. Monitor Red Hat advisories for future updates or patches.
A flaw was found in insights-client. (CVE-2026-71474)
Description
A vulnerability in insights-client causes it to log sensitive pull-secret tokens in pod logs when receiving non-200 HTTP responses at high verbosity levels. This can expose long-lived cloud.openshift.com credentials to local users with pod log access, potentially allowing unauthorized access to Red Hat cloud services. The flaw is rated medium severity with a CVSS score of 6.3. No official patch or mitigation currently meets Red Hat's criteria for deployment and ease of use.
CVSS v3.1
Score 6.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The insights-client application logs request headers, including the cloud.openshift.com pull-secret token, when it receives a non-200 response and logging verbosity is set to 3 or higher. This token is written to stderr and pod logs on the hub, making it accessible to any local user who has permission to read pod logs. This information disclosure vulnerability (CWE-532) could allow unauthorized access to Red Hat cloud services. The vulnerability has a CVSS 3.1 base score of 6.3 (medium severity) with network attack vector, high attack complexity, low privileges required, no user interaction, and a confidentiality impact only. Red Hat has not released an official fix or mitigation that meets their criteria for broad deployment.
Potential Impact
Exposure of the cloud.openshift.com pull-secret token in pod logs can lead to unauthorized access to Red Hat cloud services by local users with pod log access. The impact is limited by the need for specific logging conditions (verbosity level 3 or higher) and existing permissions to access pod logs. There is no impact on integrity or availability.
Mitigation Recommendations
Currently, no official fix or mitigation is available that meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should be aware of the risk when enabling high verbosity logging levels and restrict pod log access to trusted users only. Monitor Red Hat advisories for future updates or patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6q5x-r3rm-rpv8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71474"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7c9b6fbf8831d539ce011f
Added to database: 08/12/2026, 16:12:31 UTC
Last enriched: 08/12/2026, 17:25:17 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.