Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI
🔗 CVE IDs covered (32)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
CVE-2026-1462 — keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode
CVE-2026-2614 — mlflow: mlflow: Arbitrary file read via bypassed source path validation
CVE-2026-5241 — python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting
CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers
CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following
CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-31958 — tornado-python: Tornado: Denial of Service via large multipart bodies
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-32640 — simpleeval: SimpleEval: Arbitrary code execution via sandbox escape due to improper object handling
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
CVE-2026-33231 — nltk: NLTK: Denial of Service via unauthenticated remote shutdown
CVE-2026-33236 — nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files
CVE-2026-33245 — react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects
CVE-2026-33699 — pypdf: pypdf: Denial of Service via crafted PDF in non-strict mode
CVE-2026-34070 — langchain: path traversal in legacy load_prompt functions in langchain-core
CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()
CVE-2026-35536 — tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
CVE-2026-41242 — protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
CVE-2026-42561 — python-multipart: python-multipart: Denial of Service via excessive multipart part headers
CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header
🎯 Affected products200
- Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:0103822a274ffd4f228c0085d8b8df00a0c893f2f8d0587b7bcd6967dc86cf35_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:5175e4bc53168ebcb7c40aa10bc97d45a6eb2de865004cff4e7c094b0dd7593d_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:5847b180a0412c71dfb54398611adb5d4a4f525eaf008b1c0d8cb7e323384e58_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e90f9cdda706ae1c21b009dd3bfa080db3b06f8b4dd70fa5e655c977d0192dcd_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:5bfa629cd5481c4fe558f4c5da40965b6c1e17c5fa448a88fe52b2b9c663db23_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:b3363a8e947253da9c5daaf100c2ff4ac0f3088c916d08ac89cbd29ba6f949c0_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:f16d58a455aaab399079cf65894269e6165924a92a0d730469ae70ad0c842e20_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3a33448671868e7f6eb540a9adf1d0b544064f8494c6acdbaac2e6c9f49c4482_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5fdb1f33e2811ec60610b00f3c2dbadfd9673aa23969c5b2e6be495da9325cc2_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:b4a5fa8fb4a9f7f07f922b5d4aa92b9be30c9a2a905ca295e91be40b8a1f7b19_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f31bef6afba629e3c71da48e40c3e3f969589d38a6cefe28094cb962d7fc960e_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:8e2774be386ee281783d759dc2a1fa07715a63b2bfb62b5e71d193d73582c8d4_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:cb7872b4d404962317a2d424be01b5ab005c5e03524060bca2f4b2ac791c3161_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:ff4656f42fcdfd5c92c2da8c19571d3cdb8348fcd87707f17cec2ecb4c681c52_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:abe94761d39d697247696e2d3705172701629d9781b4890b42597d391e2d0bc8_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:b80561dcb47330dae89eb52467a571bb54ea0c98a8f5d623e25c1189d487bbe2_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:e7d55eb6ba8692054c3ee05faa50909cacec0741a936473ecca12a1765d0ec90_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:52867117af093329b0714bb63104d723ac8a00ffdb4a24393292dadd07a17a92_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:57fa6675eeeeaa01274fbb8ae28c2687609d58e790a73f182864f474ba555346_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:864a621d620f701add839a23165a969cddf762cba7bc09b911684aebecf662ab_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:16a1ace0003e1105c767d39218bc3029e5390f22a3af4c9cd9bb316e5d45d4db_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:85086943a25b84271af17d6577947d4cba80b9745a754ba8011cfc755d066387_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:b25ef77aee18028de76edab8725804ed37476405e38b3387949313fbd38e48e6_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:2cc4c9bed34fa7c1332950095e70cf354979734e8dac016f99be5afaec4de564_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:7c191c82302255ca50b047d803a20bdde14fc983e56d5c89c30fb16e0cbb7f69_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:997ff89fdc377c4e5fa2d4c68f41a3681dbaaedb6b45f32ba11a41b250e5e15f_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:33ea1f2a4f422c4fe1788a007924102e8d845b3cf6be4239fe0d42b2096dd675_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:5837840ad6cad6f21d8111cc83ff7e0fc839bf7021bee2da8e2d8c6e3da50359_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:8a8d163340b266385c962ace2129726a9bad9b82c6165a92b9ff86f59bb5ea39_ppc64le as a component of Red Hat OpenShift AI 3.3
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.3.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, ensure that the NLTK WordNet Browser HTTP server (`nltk.app.wordnet_app`) is not exposed to untrusted networks. If the WordNet Browser functionality is not required, disable or remove the component. For deployments where the server is necessary, configure firewall rules to restrict access to trusted hosts only. A service restart may be required for changes to take effect. Workaround: To mitigate this issue, ensure that any applications utilizing the NLTK downloader are configured to only interact with trusted XML index servers. Restrict network access for the application using NLTK to prevent connections to untrusted external resources. This operational control reduces the risk of an attacker controlling a malicious server to exploit the path traversal vulnerability. A service restart or reload may be required for network configuration changes to take effect. Workaround: To mitigate this Cross-Site Scripting (XSS) vulnerability, ensure that applications utilizing React Router's unstable React Server Components (RSC) APIs only process redirects from trusted sources. Avoiding the use of these unstable APIs in production environments where untrusted redirect sources cannot be guaranteed is also recommended. Workaround: To mitigate this issue, avoid processing untrusted PDF files with pypdf, particularly when operating in non-strict mode. Ensuring that applications using pypdf are configured to operate in strict mode, if supported, can prevent exploitation. Workaround: As described in the statement section, the vulnerable methods are legacy APIs and their use should be avoided. To mitigate this issue, the dumpd, dumps, load and loads methods from langchain_core.load should be used, as they supersede the legacy API and provide a more secure serialization model. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Deploying an RFC-compliant reverse proxy (such as nginx, Apache, HAProxy, or Caddy) in front of the ASGI server will reject malformed Host headers before they reach the application. This is the most straightforward mitigation that does not require code changes. If custom middleware is present, it should be updated to use `request.scope["path"]` instead of `request.url.path` for any security decisions. The ASGI scope path is derived from the HTTP request line and is not influenced by the Host header, so it reflects the actual request target.
🔗 References (36)
- selfhttps://access.redhat.com/errata/RHSA-2026:37275
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2026-1462
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-2614
- externalhttps://access.redhat.com/security/cve/CVE-2026-27893
- externalhttps://access.redhat.com/security/cve/CVE-2026-28356
- externalhttps://access.redhat.com/security/cve/CVE-2026-28684
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-31958
- externalhttps://access.redhat.com/security/cve/CVE-2026-32597
- externalhttps://access.redhat.com/security/cve/CVE-2026-32640
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33231
- externalhttps://access.redhat.com/security/cve/CVE-2026-33236
- externalhttps://access.redhat.com/security/cve/CVE-2026-33245
- externalhttps://access.redhat.com/security/cve/CVE-2026-33699
- externalhttps://access.redhat.com/security/cve/CVE-2026-34070
- externalhttps://access.redhat.com/security/cve/CVE-2026-34993
- externalhttps://access.redhat.com/security/cve/CVE-2026-35536
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39892
- externalhttps://access.redhat.com/security/cve/CVE-2026-40192
- externalhttps://access.redhat.com/security/cve/CVE-2026-41242
- externalhttps://access.redhat.com/security/cve/CVE-2026-42561
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-48710
- externalhttps://access.redhat.com/security/cve/CVE-2026-5241
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37275.json