RHSA-2026:42644HighCVSS 9.1

Red Hat Security Advisory: RHOAI 2.25.9 - Red Hat OpenShift AI

Published
July 21, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (58)

📋 Description

CVE-2024-12224 — idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded CVE-2025-14920 — transformers: code execution when processing a malicious Perceiver model file CVE-2025-14921 — transformers: code execution when processing a malicious Transformer-XL model file CVE-2025-14924 — transformers: code execution when processing a malicious megatron_gpt2 model file CVE-2025-14926 — transformers: code execution when converting a malicious SEW model checkpoint CVE-2025-14927 — transformers: code execution when converting a malicious SEW-D model checkpoint CVE-2025-14928 — transformers: code execution when converting a malicious HuBERT model checkpoint CVE-2025-14929 — transformers: code execution when processing a malicious X-CLIP model file CVE-2025-14930 — transformers: code execution when processing a malicious GLM4 model file CVE-2025-69227 — aiohttp: aiohttp: Denial of Service via specially crafted POST request CVE-2025-69228 — aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request CVE-2026-5241 — python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-11816 — keras: Keras: Arbitrary file write via path traversal in archive extraction utilities CVE-2026-22773 — vllm: vLLM: Denial of Service via specially crafted image in multimodal model serving CVE-2026-22807 — vLLM: vLLM: Arbitrary code execution via untrusted model loading CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-24486 — python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability CVE-2026-24779 — vLLM: vLLM: Server-Side Request Forgery allows internal network access CVE-2026-25048 — xgrammar: xgrammar: Denial of Service via multi-level nested syntax CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-25960 — vLLM: vLLM: Server-Side Request Forgery bypass via inconsistent URL parsing CVE-2026-25990 — pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation) CVE-2026-32981 — ray: Ray Dashboard Path Traversal Leading to Local File Disclosure CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33236 — nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files CVE-2026-33699 — pypdf: pypdf: Denial of Service via crafted PDF in non-strict mode CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-34478 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames CVE-2026-34480 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression CVE-2026-43868 — Apache Thrift: Apache Thrift: Denial of Service via excessive memory allocation CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44660 — python-ujson: UltraJSON: Memory leak leading to Denial of Service CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access CVE-2026-54293 — nltk: NLTK: Information Disclosure via Path Traversal in nltk.data.load()

🎯 Affected products200

  • Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:0ba264bf70f053344047e3b1a535bf5b5547d57ef71dd6a7c7dc12b689840ba1_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:43eeca5a1bf884667c99b1f77240622cb58a56f9c4081334a88d1801d68a9f6f_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:b20ad3101920dd67f16da5aa44feaa3adf34dc78515434122b9cd2fcfa08a116_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:f342c81a594d62f4c614ae1c9c414b1587bbd4840728cd020c16416b090c9fc1_s390x as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:74b01251f3fd3572d7cb29b065372609c1579d94022bf8e809e6e2a51e1d63f8_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:8566b3ee0cb5f6e0b6e789fe980c200c889eb7172d9ebf74bae3c27f20f593e1_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:a0c8ff589a81bc631bd3adda0788b97aab32de3c63db56e18ae133dba0e8ebf6_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:e48f70c613cc800604db3e2d3f373a7916936d89c9bcf69ca974eaace824edb2_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:88bac6f9f3f6694e9554a11a7191e6ee3a19e42e8e65a232c0df18372dcd0d0c_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:ae921fcb832d5debd6681761d59bcef32222c843e44a706e4656b00cb6c699b6_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3ec03bc01c7f28da4cf520d5b91449986ad027be1a3b11e5f506ecd5f96fe95c_s390x as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4864b6f139312eec323306271879a5c64c43ab36eb7fa69b0a747c006827dd1f_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:966deca59478cd0d25c2aa072fd67c15a2442a17ae79863b421983a0f3d2fc81_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f5a60fc46465a720de16f94d2a39266ea6d1b822aafd2d45a04a7da7ca62f82e_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:451be2cfadc78e5ebff703919bddfb2a1933a054af49d2a18da84637e621c08e_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:c15020a7e1c8faf446ea7d74228eed1e84f7548dafa4ee4040939f36fc8dde18_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:d369e709431513ff279f1ea557458a5bbc76ce5393fb22012986452199024bed_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:33b2e18e80e99d40bb5ea1daabeaab63e89b4a48943658ea4162f14d17152b3e_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:33d6a942e5c427c5a5b4c33145c4528bc7405f890c683b3b038654cb3839fa9e_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c2d9fe1bf5f5b17f4d293b9f71e534af2ad1f73e7797d5c4952566dd34d687cf_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:61b4888329b90251ae58e1c2b6680489d981e735beb26a303db7bce8d58a551b_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:648f585b9903357908c0aeb73d0bcaace95da4b4c7e018043f95dceaae452f65_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:c27f0761ea016d702a8bf150fe1613385b8a443bc1b304fea6d99b54cca9ea08_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:0af6c72e20c985dded7ce8dfa1df03c52bd8fc2bdb4114e894ed271832f4d8f1_ppc64le as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:2f7de22775a79a3bc85831a11d721aa35638115b0c2e74232061f83145ff7d03_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:6f588970f3d89998b312157a0e947a4db392675ebb72b7a795d28b9ea0d62cb1_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:81b9699ccf9d509d5990f71ecf3e87b51203c62afedd72a1715fa65cd28777c4_amd64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:830953f641026411216e3525873c301de2b0adb8fea949dd8ccd202605bbb629_arm64 as a component of Red Hat OpenShift AI 2.25
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:c75d6e96e454f1ccac4ce8e479180325dfbabe7516eb4b747813dd43886ac36b_ppc64le as a component of Red Hat OpenShift AI 2.25
  • +170 more not shown

✅ Remediation

For Red Hat OpenShift AI 2.25.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, users should avoid processing Perceiver model files from untrusted or unverified sources. Ensure that all Perceiver model files processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid processing Transformer-XL model files from untrusted or unverified sources. Ensure that all Transformer-XL model files processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid processing megatron_gpt2 model files from untrusted or unverified sources. Ensure that all megatron_gpt2 model files processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid converting SEW model checkpoints from untrusted or unverified sources. Ensure that all SEW model checkpoints processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid converting SEW-D model checkpoints from untrusted or unverified sources. Ensure that all SEW-D model checkpoints processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid converting HuBERT model checkpoints from untrusted or unverified sources. Ensure that all HuBERT model checkpoints processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid processing X-CLIP model files from untrusted or unverified sources. Ensure that all X-CLIP model files processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: To mitigate this issue, users should avoid processing GLM4 model files from untrusted or unverified sources. Ensure that all GLM4 model files processed by the Hugging Face Transformers library originate from trusted repositories or have been verified for integrity. If that is not possible, consider processing untrusted models within an isolated sandbox environment. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: To mitigate this issue, avoid extracting archives from untrusted sources. When archive extraction is necessary, ensure that the operation is performed within a dedicated, restricted directory by explicitly changing the current working directory to a non-root, isolated location before extraction. This limits the potential impact of arbitrary file writes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, ensure that vLLM instances are configured to load models only from trusted and verified repositories. Restrict access to the model repository path to prevent unauthorized modification or introduction of malicious code. Implement strict access controls and integrity checks for all model sources. Workaround: To mitigate this vulnerability, avoid enabling the `UPLOAD_KEEP_FILENAME=True` configuration option in applications using `python-multipart`. This option, when used with `UPLOAD_DIR`, allows an attacker to write files to arbitrary locations. Disabling or not configuring `UPLOAD_KEEP_FILENAME=True` prevents the path traversal vulnerability. Workaround: To mitigate this issue, restrict network access to the vLLM service to only trusted clients. Implement strict network segmentation for vLLM pods in containerized environments to limit potential lateral movement. Ensure that vLLM instances are not exposed to untrusted external networks without proper access controls and input validation at the perimeter. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, ensure that any applications utilizing the NLTK downl…

🔗 References (62)