RHSA-2026:5809HighCVSS 7.5

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (cuda-ubi9)

Published
March 25, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2025-68131 — cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse CVE-2025-69227 — aiohttp: aiohttp: Denial of Service via specially crafted POST request CVE-2025-69228 — aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request CVE-2026-25048 — xgrammar: xgrammar: Denial of Service via multi-level nested syntax CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers CVE-2026-32981 — ray: Ray Dashboard Path Traversal Leading to Local File Disclosure

🎯 Affected products3

  • Red Hat AI Inference Server 3.2
  • registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:bd371b1b8785b2f5799cbca4a12a1c66a1e8a37017334a79eaa1067b24b6a6ba_amd64 as a component of Red Hat AI Inference Server 3.2
  • registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:ee2846fae19a57151e878992484359bb834d91cada6b53c58e5c2a0b5675aa68_arm64 as a component of Red Hat AI Inference Server 3.2

✅ Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:5809 Workaround: To mitigate this issue, applications utilizing the `cbor2` library should avoid reusing `CBORDecoder` instances when processing data from different trust levels. If `CBORDecoder` reuse is unavoidable, ensure that sensitive data is not processed by a decoder instance that will subsequently handle untrusted input. This operational control prevents an attacker from accessing prior decoded information. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (10)