Red Hat Security Advisory: RHOAI 3.3.3 - Red Hat OpenShift AI
🔗 CVE IDs covered (46)
📋 Description
CVE-2025-6242 — vllm: Server Side request forgery (SSRF) in MediaConnector
CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions
CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing
CVE-2025-59057 — react-router: @remix-run/router: React Router XSS Vulnerability
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
CVE-2025-62164 — vllm: VLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-62718 — axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization
CVE-2025-64756 — glob: glob: Command Injection Vulnerability via Malicious Filenames
CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion
CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
CVE-2025-66448 — vllm: vLLM: Remote Code Execution via malicious model configuration
CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data
CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
CVE-2025-69873 — ajv: ReDoS via $data reference
CVE-2026-0846 — nltk: NLTK: Arbitrary file read via improper path validation in filestring() function
CVE-2026-0847 — nltk: NLTK: Arbitrary file read via path traversal vulnerability
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports
CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
CVE-2026-21884 — react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration
CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
CVE-2026-22778 — vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint.
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
CVE-2026-23745 — node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives
CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
CVE-2026-24486 — python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability
CVE-2026-24779 — vLLM: vLLM: Server-Side Request Forgery allows internal network access
CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig
CVE-2026-25990 — pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting
CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following
CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
CVE-2026-29074 — svgo: SVGO: Denial of Service via XML entity expansion
CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-31812 — quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-32829 — lz4_flex: lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
CVE-2026-32981 — ray: Ray Dashboard Path Traversal Leading to Local File Disclosure
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
CVE-2026-33231 — nltk: NLTK: Denial of Service via unauthenticated remote shutdown
CVE-2026-33236 — nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files
CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects
🎯 Affected products200
- Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:19c9da22376ead20a28029520ced4763919dea8cb3d057be8c345ced0d79522a_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:27da8568449150929f7ac46eb8263dbce8f6761ad151e1fbb7372dd19fa01402_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:62da88928e5329cc70031e5b8efc1754c0786ad46848ef3f864183097a261d48_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:6f82ff02df8c41f5f41b0f36f08d9c0f3be2303015c873f0811862a4d47c7bbd_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:24b7400163fbedf2aaa20eba7a798c0c928c457094503f06fb0ceccd169a730e_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:7b9eb6dd8561f2d044168b255acb90745921faeafdba32e1a5fec0e4d0def148_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:b96d6113edfcb651a31b68ec8e4c1b51a971b2318c17fbb23663f3d50eb6a4d7_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:45e842cac311df072eac4de3f25c581b224aa9580cd9af2ab7cd7769d2f9e574_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:85556c5c5fa9e335a6e6e3b97c5d6936dbe3adb47b3475625d7c22126ad6ddbf_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:bf33c3ef6432dcdba1bfe560afeed2e3f6e96c720bfd2f7e76ef799a86100474_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c70326d6062b5c9059c534f6f31e56c0424e75eda7e02c6db505879c46d81c1d_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:182d8403ab13457a57311df5f38ec1a689096ac6c68dc10019246b6c4fd4ad9b_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:3e398c7654e1d15de09613dddc1aae5fa36ce50b905fa1bf12a7d5a45f918038_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:efc7d0d195ef436f7c2b5ca0457e01c7bd6ae729b8a69a99b05a5c0bcc72d56f_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:36142cf48601711773eb282f668f9ceda4e8dd558f66334492bf3d8894c17a48_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c0a9c404327435772cdaecaeaade3ea47a14ce5b418aa268caafc75817a488f3_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:f21556fd0005b946d2763908d304b26556c828c24de94f82363a568e16d1381c_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:28f24e3455e9b8e95bef9a1af1a5c8188ec2f6ee04710e1a897b4e3332822ce6_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:2c2ca25dd00b27049f68057ec9be19465587aca362dd30c6b0a148cdc3048ae9_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:4a2caceec1fa1b564755750778ec37101429268a400ea8ed1734b27e295c1985_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:381334e801da3e4d050ed03a5b1982e09e4468d38c55ce78d9810a18792e274a_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:e737b77516202ff6c2037307add9b0e6b18e813c7272eb66f9455e32e333663d_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:ede04e6a2edb455ed0a85627a17a46f130292cb7bf52d38900806ab8847b364e_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:41f5165833f8ab076d365853684060f5844162e1476aff93e8fb7bffc7f8d44c_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:d33eaa27707972bdc372121f04178475b6baf417d96b59e5dbc55c7f5fb4489d_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:fd4f43e5c4df97bf945ff72c08fe561eac6dd27545a75ecd37139a53844a3854_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:398b0acfa6fc5ce6504eb8de531e8a3b37aa81ffaad257e7bc6d33c9128b2607_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:48911af17d0db85ec09366635c7e9e51f9a598e902544000a17db7731901d8a3_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:901f9f9de70f8124d351b1bfdffa5147270bf2971762d7c7963ec76865d2ddcf_arm64 as a component of Red Hat OpenShift AI 3.3
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.3.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, avoid using the `glob` command-line interface with the `-c` or `--cmd` option when processing filenames from untrusted sources. If programmatic use of `glob` is necessary, ensure that filenames are thoroughly sanitized before being passed to commands executed with shell interpretation enabled. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, avoid enabling the `UPLOAD_KEEP_FILENAME=True` configuration option in applications using `python-multipart`. This option, when used with `UPLOAD_DIR`, allows an attacker to write files to arbitrary locations. Disabling or not configuring `UPLOAD_KEEP_FILENAME=True` prevents the path traversal vulnerability. Workaround: To mitigate this issue, restrict network access to the vLLM service to only trusted clients. Implement strict network segmentation for vLLM pods in containerized environments to limit potential lateral movement. Ensure that vLLM instances are not exposed to untrusted external networks without proper access controls and input validation at the perimeter. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, ensure that the NLTK WordNet Browser HTTP server (`nltk.app.wordnet_app`) is not exposed to untrusted networks. If the WordNet Browser functionality is not required, disable or remove the component. For deployments where the server is necessary, configure firewall rules to restrict access to trusted hosts only. A service restart may be required for changes to take effect. Workaround: To mitigate this issue, ensure that any applications utilizing the NLTK downloader are configured to only interact with trusted XML index servers. Restrict network access for the application using NLTK to prevent connections to untrusted external resources. This operational control reduces the risk of an attacker controlling a malicious server to exploit the path traversal vulnerability. A service restart or reload may be required for network configuration changes to take effect.
🔗 References (50)
- selfhttps://access.redhat.com/errata/RHSA-2026:19712
- externalhttps://access.redhat.com/security/cve/CVE-2025-12816
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-15284
- externalhttps://access.redhat.com/security/cve/CVE-2025-59057
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-62164
- externalhttps://access.redhat.com/security/cve/CVE-2025-6242
- externalhttps://access.redhat.com/security/cve/CVE-2025-62718
- externalhttps://access.redhat.com/security/cve/CVE-2025-64756
- externalhttps://access.redhat.com/security/cve/CVE-2025-66031
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2025-66448
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-0846
- externalhttps://access.redhat.com/security/cve/CVE-2026-0847
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/cve/CVE-2026-21884
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-22778
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-23745
- externalhttps://access.redhat.com/security/cve/CVE-2026-24049
- externalhttps://access.redhat.com/security/cve/CVE-2026-24486
- externalhttps://access.redhat.com/security/cve/CVE-2026-24779
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-25990
- externalhttps://access.redhat.com/security/cve/CVE-2026-27893
- externalhttps://access.redhat.com/security/cve/CVE-2026-28684
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-29074
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-31812
- externalhttps://access.redhat.com/security/cve/CVE-2026-32597
- externalhttps://access.redhat.com/security/cve/CVE-2026-32829
- externalhttps://access.redhat.com/security/cve/CVE-2026-32981
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33231
- externalhttps://access.redhat.com/security/cve/CVE-2026-33236
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-40192
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19712.json