Red Hat Security Advisory: RHOAI 3.4.3 - Red Hat OpenShift AI
🔗 CVE IDs covered (20)
📋 Description
CVE-2026-13717 — RHOAI MaaS: llm-d: MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs) CVE-2026-14450 — maas-billing: MaaS API: Privilege escalation via forged HTTP headers due to missing authentication CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex CVE-2026-15467 — trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide CVE-2026-16456 — odh-model-controller: odh-model-controller: Cross-namespace secret read via NIM Account CRD confused deputy CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod CVE-2026-18618 — ml-metdata: Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy CVE-2026-18621 — data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening CVE-2026-18941 — feast: feast-operator: Feast: Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication CVE-2026-18942 — feast-operator: Feast: feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation CVE-2026-18948 — feast: Feast: Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server CVE-2026-18949 — odh-dashboard: odh-dashboard: ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources CVE-2026-18950 — odh-dashboard: odh-dashboard: Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole CVE-2026-18982 — odh-training-operator-rhel9: RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
🎯 Affected products133
- Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:551899da1e1be5c9a7a33cae64084475fc367a72933a17e92c67172c58793744_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:b3a09d1d083e748ef32c1d173c410a046d449a2459b496f13ad1249288b507cd_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:c70f10b4fdb9a688317dfea72e937da2989430dc69c9914a03f0eddd30445f10_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e9e2eb575f56216b410a01502409ca5c8e01a173ee3be9cab348f24d28057535_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:01ea20cdd6f845d4b493866732deb175c2bb304c1f2072177b67a54561f4f124_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5868b4761ed164f2bf50fb65bf1f569eeaaaa7141d27bd67f92df74e76924786_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:e664313bd4db6fedb5057fda3779520c577763b491787e8163a6826501a2e11f_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:e7e8d049a0c6435e3c00eb8b35c832bd844e053635be612b8f3e5d62817ad0b4_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5a85dea74addbf2e9e49bd2e7a7b68703d7ccbf7533f154def5e2ca416bfca47_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:ceb3d2e0190fcf6ab5f40907305b6daf763e1915630426928e06db3045308d64_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:f11e1d56438d896e5964c0e777cf218089e6bf46cef70636334b54cd2e070a26_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:2b13a18aff07a1ca98507815eaada3dcfe242523d83c95e53c39c85d8e4c1fd2_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:a2698a3f131da11cfbc0b680e85eac209406becb8597252050a08a8015633740_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:f4056374ebdef8c325ec6503e714bd5685b3b792904aa5941275d665b2e22693_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:0f03176447cd2236bb993f8a949e7dff3fbc696cf4fcf3d73bbe8f71932608c3_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:311838115836610e249c0e8994c07f31b73f2006945da38f0f992f87753891c7_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:df6a90d8daf4cf1e72da37742e77f47628842c0ec9d8134a2831ff9f22119cbd_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-eval-hub-rhel9@sha256:4b8921177c1f746d74be78561e8b8dedbac99f62f0a9b99feec1eb2166bb0cab_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-eval-hub-rhel9@sha256:5b0569f06c3249e5104dccdee6dee8860a843e5678ef9f31719ed9a364c1993e_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-eval-hub-rhel9@sha256:8af8c78debc978677dca3836b89b43422bbc4a4f89de652f91d64da79e133ed9_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-eval-hub-rhel9@sha256:fd84c14ecb407ce06db469778b62779df541d082c712caf682b50cd311e9424a_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:45eaf2a88eeea9f19e354b5ce07f3f32cefd508e5dc3f0d60b8c4410fa34584e_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:bdc33a2045369e0a6559a1efb43b29eff74182c194bc78c65f0a21f78f7f2351_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:fb40c0193dd60d415be0d3f0995d9efb7f4628cd105c8cc134f762d524a15a6d_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:6202cb98639928b66dc7fc6663ad0322973b11826799e77691d7756c5ccb8f31_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:9b617a6d6e3428af61f3454aa5f4207fd00016559dfc88ba450f02e3c65207ef_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:bf39e97b5a9cac6107ef760d10782a4f017954e3d3650bbecfeec96b217ced74_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:227d3864cd7009562ff2dc1e8ea8919c7913bceb3a767bff87d358268edbf3fd_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:478f456fdf7046222c3753d9798ec6d1f1293151dd769c19580e529c2c5d568f_ppc64le as a component of Red Hat OpenShift AI 3.4
- +103 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.4.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component. Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, ensure that network policies are strictly enforced to limit access to the MLMD pod's port 8080. Restrict inbound connections to only essential KFP v2 driver pods and other designated DSP components. This measure reduces the attack surface by limiting potential in-cluster attackers who could exploit the gRPC HTTP/2 denial-of-service vulnerabilities. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce `pod-security.kubernetes.io/enforce: restricted`. Additionally, verify that the `pipeline-runner` ServiceAccount is not bound to `privileged` or `anyuid` Security Context Constraints (SCCs). Workaround: To mitigate this vulnerability, configure Feast deployments to utilize Kubernetes RBAC authentication. Ensure that `FeatureStore` Custom Resources (CRs) explicitly define an authentication mechanism other than `no_auth`. For Feast SDK usage, avoid the `no_auth` setting in production environments unless `FEAST_INSECURE_NO_AUTH=1` is explicitly set, acknowledging the security implications. Applying these configuration changes will require a redeployment or restart of the affected Feast services. Workaround: Configure the Feast operator to use a dedicated, minimally-privileged ServiceAccount for the `feast apply` CronJob, ensuring `automountServiceAccountToken: false` is set. Apply a restricted `securityContext` to the CronJob pod and implement network policies to limit egress to only required registry endpoints. Ensure the CronJob ServiceAccount is separate from the feature-server ServiceAccount. Workaround: Configure Feast to enforce `auth.type: kubernetes` in the operator-generated configuration and deny registry writes by default. This measure limits the attack surface by requiring proper authentication and authorization for registry modifications, preventing the deserialization of malicious user-defined functions. Workaround: To mitigate this issue, restrict access to the `opendatahub` namespace to limit potential compromise of the dashboard pod. Implement egress `NetworkPolicy` rules to control and restrict outbound network traffic from the dashboard. Additionally, configure audit log alerting to monitor for and detect any unexpected creation of `ClusterRoleBindings` within the cluster. Workaround: To mitigate this issue, restrict access to the OpenShift AI dashboard to only trusted users. Additionally, implement an Open Policy Agent (OPA) or Gatekeeper policy to prevent the creation of RoleBindings that reference privileged ClusterRoles like cluster-admin within user namespaces. Regularly monitor audit logs for any unauthorized RoleBinding creations. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2026:53262
- externalhttps://access.redhat.com/security/cve/CVE-2026-13717
- externalhttps://access.redhat.com/security/cve/CVE-2026-14450
- externalhttps://access.redhat.com/security/cve/CVE-2026-15154
- externalhttps://access.redhat.com/security/cve/CVE-2026-15467
- externalhttps://access.redhat.com/security/cve/CVE-2026-15581
- externalhttps://access.redhat.com/security/cve/CVE-2026-16456
- externalhttps://access.redhat.com/security/cve/CVE-2026-16745
- externalhttps://access.redhat.com/security/cve/CVE-2026-18608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18611
- externalhttps://access.redhat.com/security/cve/CVE-2026-18617
- externalhttps://access.redhat.com/security/cve/CVE-2026-18618
- externalhttps://access.redhat.com/security/cve/CVE-2026-18620
- externalhttps://access.redhat.com/security/cve/CVE-2026-18621
- externalhttps://access.redhat.com/security/cve/CVE-2026-18941
- externalhttps://access.redhat.com/security/cve/CVE-2026-18942
- externalhttps://access.redhat.com/security/cve/CVE-2026-18948
- externalhttps://access.redhat.com/security/cve/CVE-2026-18949
- externalhttps://access.redhat.com/security/cve/CVE-2026-18950
- externalhttps://access.redhat.com/security/cve/CVE-2026-18951
- externalhttps://access.redhat.com/security/cve/CVE-2026-18982
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/solutions/7145755
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53262.json