Red Hat Security Advisory: RHOAI 2.25.9 - Red Hat OpenShift AI
🔗 CVE IDs covered (58)
📋 Description
CVE-2024-12224 — idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded
CVE-2025-14920 — transformers: code execution when processing a malicious Perceiver model file
CVE-2025-14921 — transformers: code execution when processing a malicious Transformer-XL model file
CVE-2025-14924 — transformers: code execution when processing a malicious megatron_gpt2 model file
CVE-2025-14926 — transformers: code execution when converting a malicious SEW model checkpoint
CVE-2025-14927 — transformers: code execution when converting a malicious SEW-D model checkpoint
CVE-2025-14928 — transformers: code execution when converting a malicious HuBERT model checkpoint
CVE-2025-14929 — transformers: code execution when processing a malicious X-CLIP model file
CVE-2025-14930 — transformers: code execution when processing a malicious GLM4 model file
CVE-2025-69227 — aiohttp: aiohttp: Denial of Service via specially crafted POST request
CVE-2025-69228 — aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request
CVE-2026-5241 — python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
CVE-2026-11816 — keras: Keras: Arbitrary file write via path traversal in archive extraction utilities
CVE-2026-22773 — vllm: vLLM: Denial of Service via specially crafted image in multimodal model serving
CVE-2026-22807 — vLLM: vLLM: Arbitrary code execution via untrusted model loading
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
CVE-2026-24486 — python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability
CVE-2026-24779 — vLLM: vLLM: Server-Side Request Forgery allows internal network access
CVE-2026-25048 — xgrammar: xgrammar: Denial of Service via multi-level nested syntax
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-25960 — vLLM: vLLM: Server-Side Request Forgery bypass via inconsistent URL parsing
CVE-2026-25990 — pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting
CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers
CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-32981 — ray: Ray Dashboard Path Traversal Leading to Local File Disclosure
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
CVE-2026-33236 — nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files
CVE-2026-33699 — pypdf: pypdf: Denial of Service via crafted PDF in non-strict mode
CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-34478 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames
CVE-2026-34480 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging
CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
CVE-2026-43868 — Apache Thrift: Apache Thrift: Denial of Service via excessive memory allocation
CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation
CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-44660 — python-ujson: UltraJSON: Memory leak leading to Denial of Service
CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access
CVE-2026-54293 — nltk: NLTK: Information Disclosure via Path Traversal in nltk.data.load()
🔗 References (62)
- selfhttps://access.redhat.com/errata/RHSA-2026:42644
- externalhttps://access.redhat.com/security/cve/CVE-2024-12224
- externalhttps://access.redhat.com/security/cve/CVE-2025-14920
- externalhttps://access.redhat.com/security/cve/CVE-2025-14921
- externalhttps://access.redhat.com/security/cve/CVE-2025-14924
- externalhttps://access.redhat.com/security/cve/CVE-2025-14926
- externalhttps://access.redhat.com/security/cve/CVE-2025-14927
- externalhttps://access.redhat.com/security/cve/CVE-2025-14928
- externalhttps://access.redhat.com/security/cve/CVE-2025-14929
- externalhttps://access.redhat.com/security/cve/CVE-2025-14930
- externalhttps://access.redhat.com/security/cve/CVE-2025-69227
- externalhttps://access.redhat.com/security/cve/CVE-2025-69228
- externalhttps://access.redhat.com/security/cve/CVE-2026-11816
- externalhttps://access.redhat.com/security/cve/CVE-2026-22773
- externalhttps://access.redhat.com/security/cve/CVE-2026-22807
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-24486
- externalhttps://access.redhat.com/security/cve/CVE-2026-24779
- externalhttps://access.redhat.com/security/cve/CVE-2026-25048
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-25960
- externalhttps://access.redhat.com/security/cve/CVE-2026-25990
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-27893
- externalhttps://access.redhat.com/security/cve/CVE-2026-28356
- externalhttps://access.redhat.com/security/cve/CVE-2026-28684
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-32597
- externalhttps://access.redhat.com/security/cve/CVE-2026-32981
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33236
- externalhttps://access.redhat.com/security/cve/CVE-2026-33699
- externalhttps://access.redhat.com/security/cve/CVE-2026-33747
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-34478
- externalhttps://access.redhat.com/security/cve/CVE-2026-34480
- externalhttps://access.redhat.com/security/cve/CVE-2026-34993
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39892
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-42578
- externalhttps://access.redhat.com/security/cve/CVE-2026-42581
- externalhttps://access.redhat.com/security/cve/CVE-2026-42584
- externalhttps://access.redhat.com/security/cve/CVE-2026-42587
- externalhttps://access.redhat.com/security/cve/CVE-2026-43868
- externalhttps://access.redhat.com/security/cve/CVE-2026-43869
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44660
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-48746
- externalhttps://access.redhat.com/security/cve/CVE-2026-5241
- externalhttps://access.redhat.com/security/cve/CVE-2026-54293
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42644.json