Redhat

Openshift Ai

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 23.07.2026 10:41:30
  • Zuletzt bearbeitet 30.09.2026 17:16:44

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access t...

  • EPSS 0.26%
  • Veröffentlicht 13.07.2026 08:01:26
  • Zuletzt bearbeitet 13.07.2026 17:01:11

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. T...

  • EPSS 0.26%
  • Veröffentlicht 10.07.2026 15:25:09
  • Zuletzt bearbeitet 31.08.2026 14:17:13

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server...

  • EPSS 0.32%
  • Veröffentlicht 10.07.2026 09:29:55
  • Zuletzt bearbeitet 30.09.2026 17:16:44

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unautho...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 20:16:48
  • Zuletzt bearbeitet 30.09.2026 17:16:43

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detect...

  • EPSS 0.18%
  • Veröffentlicht 08.07.2026 14:58:12
  • Zuletzt bearbeitet 31.08.2026 15:17:10

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster netwo...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 14:37:22
  • Zuletzt bearbeitet 31.08.2026 16:17:52

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their iden...

  • EPSS 0.57%
  • Veröffentlicht 23.06.2026 12:12:51
  • Zuletzt bearbeitet 26.09.2026 23:10:00

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote ...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 10.06.2026 21:18:05
  • Zuletzt bearbeitet 09.09.2026 13:20:18

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON objec...

Warnung Medienbericht Exploit
  • EPSS 1.84%
  • Veröffentlicht 26.05.2026 22:16:44
  • Zuletzt bearbeitet 01.10.2026 18:17:18

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` ...