Red Hat Security Advisory: RHOAI 2.25.6 - Red Hat OpenShift AI
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:00c2d3d03d54c4526dbedc294c67dfdd518eb9355dbc1b0fc7cc1d8eb91d1341_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:579f7cffd7099b9641d123e89cdf10e6e4eefa6ccc407defeeec111b22947e70_s390x as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:d928f6ef8486b2dda90c53c7c076fd8d4ec9660463c5e4a71b44449f12342673_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e9b410808a246ee9f3990c0600e7e3315cc8d056ccb82deb5ebad04ce61edf01_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:3789bf57cbc86202e77f2bc4b424ce34b99656ca8e2aaaca6fa6a6797fe8462f_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:3baa94b8a1991a847df172cfcc24ab8db758a8dc11a1bc1be3018a357ce89732_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:829c505373cef012fcaee9f1665c7c5fcfd97b19df58be310e5e5fc9df6fabe7_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:fed037a7c85d84077ca48be53cbcad61b1ce3584c1a1fc68282da92e253bcbc1_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:05f93da42974d588250555927190324f55d83f429cdc4d1d74357e51dd2964ab_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:a66fe9cce409bda87eec0745e247704f5409b5fd35d5a67dea08d54e1ce53a1a_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:12f28ae6823c84db2a05c44bb8d5dfeefac62497e0ee254c0b7aa82956163460_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:520ae6502bd7db77b2db50d5d0fe550722f1760cc4c30f7f34e5f85d9130c15f_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:7519626974fd14a15b9d13e283cfa387b4d934f31caccc2bd0a71c2d065e8c95_s390x as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:d574464b198120916e5689da33aece789d98b4bf7342eb2a24114bd8e5236c87_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:1d7f56da1c8fbda4a33bd6be60bff726bd3ea6b5bd6e5415372b2752520d0a89_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:57d22c8255832cd23dd894528f06af85a3ba3957db2099573cf44322803df905_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:bb331e9ad8f40e3059743fc9f54d332fc4929ac7530d13e827144c44fb737f67_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:221d5a9774f568142b322ee82fd8653c36bf10c281518a49d53143174753e872_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:6c9ac700f777919105624c5f8f4dd48ff1c7f12f3d9a416c5b5e5856bb03d0b2_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:f1715ab14f6a76dc4c1d64d6040fe994495fdb6de03be360ae46ebb3225418b3_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:1ec8f03dc554a5de5b704f0ce67eb9e4a1e84e2ca4bff115e2371956cc5b2b4d_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:da5795222dc70000f535ea3a6f2baa3f8d16927e33906aba0911bb1539a34a3b_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:e3838055d17e42929737cdcc1f4fa278c19a9cc9a88c489c3771deee37d922fc_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:51592076cb1952b37ecb4ef2c36a1d74d1f3c7c8b962c72247b0a6e26784f9fe_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:de8b62bfb83b9b34ed29fbad3806e24be622a3de7363077ddafd3d8438abea74_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:f5338e7e6348b327cb6258f9c2dda85c18df4faed7dbec3a10ce37ae2da9e23d_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:6ba093a6293bfafa7d1b7aacfc0480edbe3a9e4e32fb778143d989246c62b801_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:890e65df74fb9597445fb8a6edc2d1886388e6aafdf27a2d3c0d91a5e83d35ce_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:b09f9f86ca9c5e7f3097236bc93b4c1a94785b6894c1c7bdbcb35c59df2d38ac_amd64 as a component of Red Hat OpenShift AI 2.25
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 2.25.6 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:10698
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10698.json