Red Hat Security Advisory: RHOAI 3.3.6 - Red Hat OpenShift AI
🔗 CVE IDs covered (18)
📋 Description
CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex CVE-2026-15467 — trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide CVE-2026-16456 — odh-model-controller: odh-model-controller: Cross-namespace secret read via NIM Account CRD confused deputy CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod CVE-2026-18618 — ml-metdata: Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy CVE-2026-18621 — data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening CVE-2026-18941 — feast: feast-operator: Feast: Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication CVE-2026-18947 — feast: Feast: Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization CVE-2026-18948 — feast: Feast: Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server CVE-2026-18949 — odh-dashboard: odh-dashboard: ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources CVE-2026-18950 — odh-dashboard: odh-dashboard: Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole CVE-2026-18982 — odh-training-operator-rhel9: RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
🎯 Affected products98
- Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:060c8cfa5da0f39e670b657bbf675685c609d2f060fbead6f3135c9e9cf26a66_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:9baf53fb4f1395596104c48e58eca01ec4b4bb445d3a5d6b03fc5ee782500975_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:c11d85206d14bbe4dbdfb9405a67aa37c74010b967cac0d435890458a171299f_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:c7a0bfdc527692a60afc897e5ebee5540402bf88842be05db89fe9864b5043bd_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:19d7eb376594ebd87d118236fed224820f650c19e5c2c621577bf1e1f27edca1_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:214ec254ee5857e00ffbbb7c7bab39c1659537a00a87ab2a05ba55b16a7897bc_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:63fed16c4f462616db4c2577682f6553f771f02fbbf8134cbb4699542e0f0126_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:bce84f2d0d1a91fe190dc4aa67e3208427ec9496a4b425960614239c9bdaca9d_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:21dcc76464d782d8bf5c5fdf54c9e0a25019966ffdb5e4ec4d480a768e3aad20_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:4b3685ec9b39683873a4ed73c5ffc45ab909dd4519f0e7adaae3ee27b24a4def_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5f6007f40f6bae0a9829a1ae86ee0c77c77e3d9d8d6b7a6fe1706527d39e4bf6_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:616a51a4e2dfa5bffb1758f67c7a4dd0b717280f22a44df9a98f55d27dee9b24_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:6685c545e3f96df81f5a73d4b02883e5383723e791589cd07b54952a041ff0e3_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:b9cb77525d57611ed7d9c02445f717189debae79b54e1f8fbee267373b02fa03_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:5458629cd0e8d2a3fc50403c3c7f7f789a1e4695771aa6fe2de79e6609a16121_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:abdbd12b164305bb687eea036d4c6d799434dcce6a6579d54cb66ec1459db9f8_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:b75512bc1ef0d56f7d7f3b2f2551f2ab9e246c804d60b5275d24be4992707cdd_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:3035985012078c42a0ea132ff9dbbde5cf051b5c491c8670f14792ace1da8b3a_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:ce367be69e827a6b1a1b5dc077758dfaae16a68d5003ad8c4aba80dce974d13b_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:e2d3acec5ab78792e1a738f8d80ca7d1cc63c99ee30c9c673108ac969c5f8adb_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:5ae49aa23a8060a23d0d811d6ba936d450d273a6ba2cd260e1bbb85ae47a9f84_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:d3e4c25c477d80f3e861d6b04a10d1f9869c093a5c6ec0666c8d66d237ebe36c_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:df14db5d20c76ec58ec9561940a2c29052d033dc5fd6a3d3872a5da75bbb12b4_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:13852081863a6553827e7f7444c95b7e846a331d830b866637fc9d2680508c95_amd64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:75a801c4d3ae2592367970887896ea444e4a9591012a5709eb8e91b307cfd22f_ppc64le as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:8e2c8e10ce136c5644c447a076295ecb121d4b4a3555d5ca33f53c728ccb7aaa_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-guardrails-detector-huggingface-runtime-rhel9@sha256:e0a982643352c5fcf7eab9b26cc93f9f45a725dd270b4a1a922d345e6449e2fd_arm64 as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-kf-notebook-controller-rhel9@sha256:1995cdf9136292c9b1cd2795dee252427ee5534891e8f9434524fdf43f0a70ca_s390x as a component of Red Hat OpenShift AI 3.3
- registry.redhat.io/rhoai/odh-kf-notebook-controller-rhel9@sha256:94a81fd8327b7b6f9dbfb12fb91a35195a102ea117f63ba29f9865cd39171132_amd64 as a component of Red Hat OpenShift AI 3.3
- +68 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.3.6 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, ensure that network policies are strictly enforced to limit access to the MLMD pod's port 8080. Restrict inbound connections to only essential KFP v2 driver pods and other designated DSP components. This measure reduces the attack surface by limiting potential in-cluster attackers who could exploit the gRPC HTTP/2 denial-of-service vulnerabilities. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce `pod-security.kubernetes.io/enforce: restricted`. Additionally, verify that the `pipeline-runner` ServiceAccount is not bound to `privileged` or `anyuid` Security Context Constraints (SCCs). Workaround: To mitigate this vulnerability, configure Feast deployments to utilize Kubernetes RBAC authentication. Ensure that `FeatureStore` Custom Resources (CRs) explicitly define an authentication mechanism other than `no_auth`. For Feast SDK usage, avoid the `no_auth` setting in production environments unless `FEAST_INSECURE_NO_AUTH=1` is explicitly set, acknowledging the security implications. Applying these configuration changes will require a redeployment or restart of the affected Feast services. Workaround: To mitigate this vulnerability, restrict network access to the Feast feature server to trusted clients only, using firewall rules or network policies. If the Feast feature server is configured with the default `no_auth` setting, enable Kubernetes/OIDC authentication to require user authentication for access. While enabling authentication will prevent unauthenticated exploitation, any authenticated user will still be able to trigger the denial of service due to the authorization bypass. Workaround: Configure Feast to enforce `auth.type: kubernetes` in the operator-generated configuration and deny registry writes by default. This measure limits the attack surface by requiring proper authentication and authorization for registry modifications, preventing the deserialization of malicious user-defined functions. Workaround: To mitigate this issue, restrict access to the `opendatahub` namespace to limit potential compromise of the dashboard pod. Implement egress `NetworkPolicy` rules to control and restrict outbound network traffic from the dashboard. Additionally, configure audit log alerting to monitor for and detect any unexpected creation of `ClusterRoleBindings` within the cluster. Workaround: To mitigate this issue, restrict access to the OpenShift AI dashboard to only trusted users. Additionally, implement an Open Policy Agent (OPA) or Gatekeeper policy to prevent the creation of RoleBindings that reference privileged ClusterRoles like cluster-admin within user namespaces. Regularly monitor audit logs for any unauthorized RoleBinding creations. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2026:53263
- externalhttps://access.redhat.com/security/cve/CVE-2026-15154
- externalhttps://access.redhat.com/security/cve/CVE-2026-15467
- externalhttps://access.redhat.com/security/cve/CVE-2026-15581
- externalhttps://access.redhat.com/security/cve/CVE-2026-16456
- externalhttps://access.redhat.com/security/cve/CVE-2026-16745
- externalhttps://access.redhat.com/security/cve/CVE-2026-18608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18611
- externalhttps://access.redhat.com/security/cve/CVE-2026-18617
- externalhttps://access.redhat.com/security/cve/CVE-2026-18618
- externalhttps://access.redhat.com/security/cve/CVE-2026-18620
- externalhttps://access.redhat.com/security/cve/CVE-2026-18621
- externalhttps://access.redhat.com/security/cve/CVE-2026-18941
- externalhttps://access.redhat.com/security/cve/CVE-2026-18947
- externalhttps://access.redhat.com/security/cve/CVE-2026-18948
- externalhttps://access.redhat.com/security/cve/CVE-2026-18949
- externalhttps://access.redhat.com/security/cve/CVE-2026-18950
- externalhttps://access.redhat.com/security/cve/CVE-2026-18951
- externalhttps://access.redhat.com/security/cve/CVE-2026-18982
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/solutions/7145755
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53263.json