CVE-2026-16745
- EPSS 0.27%
- Veröffentlicht 23.07.2026 10:41:30
- Zuletzt bearbeitet 30.09.2026 17:16:44
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access t...
CVE-2026-15574
- EPSS 0.26%
- Veröffentlicht 13.07.2026 08:01:26
- Zuletzt bearbeitet 13.07.2026 17:01:11
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. T...
CVE-2026-15143
- EPSS 0.26%
- Veröffentlicht 10.07.2026 15:25:09
- Zuletzt bearbeitet 31.08.2026 14:17:13
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server...
CVE-2026-15378
- EPSS 0.32%
- Veröffentlicht 10.07.2026 09:29:55
- Zuletzt bearbeitet 30.09.2026 17:16:44
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unautho...
CVE-2026-15154
- EPSS 0.3%
- Veröffentlicht 08.07.2026 20:16:48
- Zuletzt bearbeitet 30.09.2026 17:16:43
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detect...
CVE-2026-15063
- EPSS 0.18%
- Veröffentlicht 08.07.2026 14:58:12
- Zuletzt bearbeitet 31.08.2026 15:17:10
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster netwo...
CVE-2026-15044
- EPSS 0.17%
- Veröffentlicht 08.07.2026 14:37:22
- Zuletzt bearbeitet 31.08.2026 16:17:52
A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their iden...
CVE-2023-54365
- EPSS 0.57%
- Veröffentlicht 23.06.2026 12:12:51
- Zuletzt bearbeitet 26.09.2026 23:10:00
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote ...
CVE-2026-46625
- EPSS 0.67%
- Veröffentlicht 10.06.2026 21:18:05
- Zuletzt bearbeitet 09.09.2026 13:20:18
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON objec...
CVE-2026-48710
- EPSS 1.84%
- Veröffentlicht 26.05.2026 22:16:44
- Zuletzt bearbeitet 01.10.2026 18:17:18
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` ...