Red Hat Security Advisory: RHOAI 3.5 - Red Hat OpenShift AI
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-66626 — github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-15467 — trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod CVE-2026-18618 — ml-metdata: Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole CVE-2026-18982 — odh-training-operator-rhel9: RHOAI fork aggregates training job create onto native edit/admin ClusterRoles CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-64849 — mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
🎯 Affected products5
- Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-latency-predictor-prediction-rhel9@sha256:5743e64bd3a2947dc022830f2d769f4ff90daf04b3e6dcfaba6420815cdb52e5_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-latency-predictor-prediction-rhel9@sha256:ada20174176992b0ee306e6eface5bff06f06a71783f3deccd530a5bc4fe80a1_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-latency-predictor-training-rhel9@sha256:4f1a03f0801811aea4550346a041c079d1cbb80cdb6f128a513122eebe3f2cef_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-latency-predictor-training-rhel9@sha256:5bdb27b5f11d3057f9087b1e08e68b13e107541d595cbf9066d4f7a96a472ae9_amd64 as a component of Red Hat OpenShift AI 3.5
✅ Remediation
For Red Hat OpenShift AI 3.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, ensure that network policies are strictly enforced to limit access to the MLMD pod's port 8080. Restrict inbound connections to only essential KFP v2 driver pods and other designated DSP components. This measure reduces the attack surface by limiting potential in-cluster attackers who could exploit the gRPC HTTP/2 denial-of-service vulnerabilities. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect. Workaround: To reduce the attack surface for this vulnerability, restrict network access to the MLflow server. Implement firewall rules or network access controls to limit connectivity to the MLflow instance from untrusted networks. This operational control helps prevent unauthenticated attackers from reaching the vulnerable webhook test endpoint.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:60367
- externalhttps://access.redhat.com/security/cve/CVE-2025-66626
- externalhttps://access.redhat.com/security/cve/CVE-2026-15467
- externalhttps://access.redhat.com/security/cve/CVE-2026-15581
- externalhttps://access.redhat.com/security/cve/CVE-2026-18608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18611
- externalhttps://access.redhat.com/security/cve/CVE-2026-18617
- externalhttps://access.redhat.com/security/cve/CVE-2026-18618
- externalhttps://access.redhat.com/security/cve/CVE-2026-18620
- externalhttps://access.redhat.com/security/cve/CVE-2026-18951
- externalhttps://access.redhat.com/security/cve/CVE-2026-18982
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-64849
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60367.json