Redhat

Openshift Ai

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 13.07.2026 08:01:26
  • Zuletzt bearbeitet 13.07.2026 17:01:11

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. T...

  • EPSS 0.26%
  • Veröffentlicht 10.07.2026 15:25:09
  • Zuletzt bearbeitet 10.07.2026 17:49:57

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server...

  • EPSS 0.32%
  • Veröffentlicht 10.07.2026 09:29:55
  • Zuletzt bearbeitet 14.07.2026 02:16:54

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unautho...

  • EPSS 0.3%
  • Veröffentlicht 08.07.2026 20:16:48
  • Zuletzt bearbeitet 11.08.2026 19:17:20

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detect...

  • EPSS 0.18%
  • Veröffentlicht 08.07.2026 14:58:12
  • Zuletzt bearbeitet 09.07.2026 16:39:17

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster netwo...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 14:37:22
  • Zuletzt bearbeitet 14.07.2026 14:16:32

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their iden...

  • EPSS 0.57%
  • Veröffentlicht 23.06.2026 12:12:51
  • Zuletzt bearbeitet 15.07.2026 02:17:08

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote ...

Warnung Medienbericht
  • EPSS 83.01%
  • Veröffentlicht 08.05.2026 03:35:16
  • Zuletzt bearbeitet 15.07.2026 02:21:30

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 13.04.2026 14:55:28
  • Zuletzt bearbeitet 15.07.2026 02:18:14

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarante...

  • EPSS 0.49%
  • Veröffentlicht 10.04.2026 17:33:25
  • Zuletzt bearbeitet 15.07.2026 01:16:42

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable...