RHSA-2025:22068HighCVSS 8.4

Red Hat Security Advisory: RHTAS 1.3.1 - Tech Preview Release of Model Transparency

Published
November 25, 2025
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-49655 — keras: Keras deserialization of untrusted data

🎯 Affected products2

  • Red Hat Trusted Artifact Signer 1.3
  • registry.redhat.io/rhtas/model-transparency-rhel9@sha256:cdbf79af3951e2830df94331a890ab8f1e2649db72e96bec57fee61fc9add1e6_amd64 as a component of Red Hat Trusted Artifact Signer 1.3

✅ Remediation

The Model Transparency CLI Image is a containerized command-line tool for signing and verifying AI/ML workloads against a private Red Hat Trusted Artifact Signer (RHTAS) instance. It lets teams create signatures and attestations for model artifacts and validate them at build or deploy time using enterprise trust material (e.g., Fulcio/Rekor). For details on using the Model Transparency CLI image, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)