RHSA-2026:60520CriticalCVSS 9.9

Red Hat Security Advisory: RHOAI 3.4.4 - Red Hat OpenShift AI

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (143)

CVE-2026-44020CVE-2026-46597CVE-2026-46625CVE-2026-59204CVE-2026-5241CVE-2026-15378CVE-2026-15581CVE-2026-18621CVE-2026-42311CVE-2026-44018CVE-2026-12481CVE-2026-27136CVE-2026-42266CVE-2026-44293CVE-2026-44724CVE-2026-45740CVE-2026-59884CVE-2026-15467CVE-2026-18620CVE-2026-42215CVE-2026-44486CVE-2026-45292CVE-2026-59205CVE-2026-41672CVE-2026-12151CVE-2026-13717CVE-2026-64835CVE-2026-18617CVE-2026-42284CVE-2026-42338CVE-2026-42502CVE-2026-44496CVE-2026-55379CVE-2026-42305CVE-2025-71330CVE-2026-9697CVE-2026-15218CVE-2026-44240CVE-2026-44289CVE-2026-49477CVE-2026-39828CVE-2026-48801CVE-2026-64849CVE-2026-12143CVE-2026-44244CVE-2026-44290CVE-2026-44513CVE-2025-66471CVE-2026-18608CVE-2026-32280CVE-2026-44494CVE-2026-44705CVE-2026-59200CVE-2026-69243CVE-2026-0545CVE-2026-6322CVE-2026-15154CVE-2026-18611CVE-2026-42211CVE-2026-59874CVE-2026-59886CVE-2026-18948CVE-2026-33814CVE-2026-56210CVE-2026-8643CVE-2026-25681CVE-2026-33811CVE-2026-44292CVE-2026-44488CVE-2026-55685CVE-2026-56208CVE-2026-59199CVE-2025-66626CVE-2026-44495CVE-2026-44727CVE-2026-55380CVE-2026-39831CVE-2026-42499CVE-2026-45623CVE-2026-50193CVE-2026-13311CVE-2026-39830CVE-2026-42508CVE-2026-59197CVE-2026-59885CVE-2026-44487CVE-2026-49978CVE-2026-41675CVE-2026-32283CVE-2026-35397CVE-2026-46595CVE-2026-53550CVE-2026-56209CVE-2026-56211CVE-2026-5422CVE-2026-13149CVE-2026-18951CVE-2026-39820CVE-2026-44291CVE-2026-44843CVE-2026-48526CVE-2026-48710CVE-2026-16745CVE-2026-33245CVE-2026-40171CVE-2026-42342CVE-2026-44660CVE-2026-69192CVE-2026-12243CVE-2026-39821CVE-2026-42264CVE-2026-54058CVE-2026-54060CVE-2026-54283CVE-2026-2614CVE-2026-33079CVE-2026-44492CVE-2026-49851CVE-2026-41673CVE-2026-56121CVE-2026-6734CVE-2026-39829CVE-2026-49476CVE-2026-13676CVE-2026-14450CVE-2026-45804CVE-2026-47214CVE-2026-48779CVE-2026-54293CVE-2026-59869CVE-2026-69152CVE-2026-34993CVE-2026-44017CVE-2026-69244CVE-2025-71329CVE-2026-44827CVE-2026-45736CVE-2026-59873CVE-2026-18982CVE-2026-39835CVE-2026-42557CVE-2026-48712CVE-2026-58049

📋 Description

CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-66626 — github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links CVE-2025-71329 — image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field CVE-2025-71330 — image-size: image-size: Denial of Service via crafted ICNS image buffer CVE-2026-0545 — mlflow/mlflow: mlflow/mlflow: Unauthenticated remote code execution via unprotected job endpoints CVE-2026-2614 — mlflow: mlflow: Arbitrary file read via bypassed source path validation CVE-2026-5241 — python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting CVE-2026-5422 — jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-12243 — nltk: NLTK: Information disclosure via path traversal vulnerability CVE-2026-12481 — keras: Keras: Arbitrary code execution via deserialization vulnerability CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13311 — shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-13717 — RHOAI MaaS: llm-d: MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs) CVE-2026-14450 — maas-billing: MaaS API: Privilege escalation via forged HTTP headers due to missing authentication CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex CVE-2026-15218 — models-as-a-service: Red Hat OpenShift AI: maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation CVE-2026-15378 — guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:) CVE-2026-15467 — trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy CVE-2026-18621 — data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening CVE-2026-18948 — feast: Feast: Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole CVE-2026-18982 — odh-training-operator-rhel9: RHOAI fork aggregates training job create onto native edit/admin ClusterRoles CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33079 — mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input CVE-2026-33245 — react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-35397 — jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-40171 — Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting CVE-2026-41672 — xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection CVE-2026-41673 — @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents CVE-2026-41675 — xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions CVE-2026-42211 — react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation CVE-2026-42266 — jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-42305 — dulwich: Dulwich: Remote Code Execution via Malicious Git Repository CVE-2026-42311 — Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-42342 — react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-42557 — jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output CVE-2026-44017 — docling: Docling: Remote code execution via Zip Slip vulnerability in model download CVE-2026-44018 — docling: Docling: Denial of Service via crafted document archives CVE-2026-44020 — docling: Docling: Information disclosure via XML External Entity (XXE) vulnerability CVE-2026-44240 — basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-44289 — protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding CVE-2026-44290 — protobufjs: protobufjs: Denial of Service via crafted schema CVE-2026-44291 — protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution CVE-2026-44292 — protobufjs: protobufjs: Data integrity impact due to prototype pollution CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-44513 — Diffusers: Diffusers: Arbitrary remote code execution via trust_remote_code bypass CVE-2026-44660 — python-ujson: UltraJSON: Memory leak leading to Denial of Service CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-44724 — systeminformation: systeminformation: Command injection via NetworkManager connection profile name CVE-2026-44727 — jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers CVE-2026-44827 — diffusers: Diffusers: Arbitrary Code Execution via malicious model loading CVE-2026-44843 — langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization CVE-2026-45292 — opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-45740 — protobufjs: protobufjs: Denial of Service via crafted JSON descriptors CVE-2026-45804 — diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-46625 — js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution CVE-2026-47214 — docling: Docling: Unsafe URI and Path Handling in HTML Backend CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header CVE-2026-48712 — protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-49476 — python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-49851 — Mistune: Mistune: Denial of Service via crafted Markdown input CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-50193 — jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing CVE-2026-53550 — js-yaml: js-yaml: Denial of Service via crafted YAML merge keys CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS CVE-2026-54293 — nltk: NLTK: Information Disclosure via Path Traversal in nltk.data.load() CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file CVE-2026-55685 — react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests CVE-2026-56121 — feast: Feast: Remote Code Execution via Unsafe Deserialization in gRPC Registry Server CVE-2026-56208 — libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode CVE-2026-56209 — libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack CVE-2026-56210 — libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id CVE-2026-56211 — libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames CVE-2026-58049 — FFmpeg: FFmpeg: Memory corruption via crafted RASC video stream CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header CVE-2026-59884 — python-pyasn1: pyasn1: Denial of Service via crafted BER input CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files CVE-2026-64849 — mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses

🎯 Affected products200

  • Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:170e78670297c1c9435cff22c3f227edd58dc30993ebd0cb3d8265de838210af_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:2f83d14f149aa832849e346b90fb4449ba3511bb56108cfeebe295b627c1cb80_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:5cb9fb802c5439bd68d14df430144da061675fdd70f1b38a07284e0e5c8b3894_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:617d5a2b3008ad195f6f26692ff9a8ee6ebb2a940b39b7245916af517b130a90_s390x as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-automl-rhel9@sha256:11140a858c6fd3174d63e845f7d0bd451e67d50adc3befbfac57659d6334dfef_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-automl-rhel9@sha256:2d169d86c2e33636fbfce62d08d85e266bde276a7ea24ea205e921a9633e3008_s390x as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-automl-rhel9@sha256:81087b35bd99aff8fc8db0918bc613b96e4d9a3eafff3a27078185c06412b6d1_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-automl-rhel9@sha256:b49858f38add2b26168ac0437524cf9829cbbc4812e4fcd1347915da2df3afb8_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:719e138a13ad9cfaff20cb03295538c85dda4fc051ff866b25e04f1be8456ea4_s390x as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:8404758b6b7609b6728f3d464560221bb0250e82406ec879cfcb50819e19f201_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:9a5f6e83add8f4ec9f41284ee9c1a689cb193c1be7bd3860256bb612355e2631_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:c7b9ca039c7ed15d23bd819cb6d6f45748cf2f86f7096ebc2db31b1d0f3c1e70_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:3037ef27d81723dbe3ca98bf55c5c93fff42f3fad5935559cbf6eb272778ed7f_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:b017469cbd901503271b8944df40a74cf408c5223a880c696448f2b098b7c112_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:bddfb02d685a2511cbf83bf8c6fba7872864b411adcb06d272bbfda89882883a_s390x as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e7d23a7fa4026469af734196cc0f56d5fdadd79eb5d04bb77c152019356ab679_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-cli-rhel9@sha256:07f8ee936a6fc58fb75dd487034dbe308db6c2a566c340922aefba4bd66c7c92_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-cli-rhel9@sha256:db345b46ed71b50223ee62c58a1a70198e2d728fca81550a81a932d5d7e718f6_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c7daef8e89de0e096983b72e81eeae966cea075874f1ddc498e0f92b9d5a278d_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:dbaf78b7927d84af5cb0839937541970959ad7c22238e0ba1128eaf7605968b2_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f3ee104a6bda47b1fd75494d5cde518327d39a5b1e3db2353e3103a77d75baf0_s390x as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5b32f727afed4fe60f0c1f53d05bc0345e2b02c55c9882de10cb376366686461_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:775c307e1cfb3f68cfc081aafc9d968ace5ff88b5407e4365bb46d9ab7fcf609_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:9fa5ec6f9e81cb122f732887a065272bcd98448180923be0024c541bee75b7e1_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:6838e7e122464c2a2afbc1ec7294c6bea54a59110cfcd090e17e462aa99050e7_amd64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c8bcf379905652e7822492d03f18cbac2e92421055a6f760b8a3ec1ec712b6a1_ppc64le as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c9ccf4e8a33568b7dcc701f59d51b913607424bf95e8b51709911cf3e690db51_arm64 as a component of Red Hat OpenShift AI 3.4
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:201cc48366e9650b4524b83352e72289bf62235a7ab9aa2903eb4ebee2ae83ee_arm64 as a component of Red Hat OpenShift AI 3.4
  • +170 more not shown

✅ Remediation

For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Upgrade to a version of image-size that validates box size fields. As a workaround, validate image inputs before passing them to image-size, rejecting files with zero-length box entries. Workaround: Upgrade to a version of image-size that validates ICNS entry length fields. As a workaround, validate image inputs before passing them to image-size, rejecting ICNS files with zero-length entries. Workaround: To mitigate this issue, disable job execution on the MLflow server by setting the `MLFLOW_SERVER_ENABLE_JOB_EXECUTION` environment variable to `false`. This prevents unauthenticated access to job endpoints. Example: `MLFLOW_SERVER_ENABLE_JOB_EXECUTION=false mlflow server` If configured as a service, update the service definition to include this environment variable. A restart of the MLflow server is required for the change to take effect. Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Do not pass untrusted or user-controlled input directly to nltk.data.load() or nltk.data.find(). Validate and sanitize any resource name parameter before use, rejecting values containing percent-encoded characters (%2f, %2e) or path traversal sequences. As defense-in-depth, set nltk.pathsec.ENFORCE = True in application code to enable file-read restrictions at the open stage (disabled by default). Workaround: To reduce exposure, only deserialize Keras models from trusted sources. When deserializing models, explicitly enable `safe_mode` by wrapping the deserialization call within a `SafeModeScope(True)` context. This ensures the deserialization safeguard is enforced, preventing the execution of arbitrary code. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Upgrade shell-quote to version 1.8.5. If upgrading shell-quote to version 1.8.5 or later is not immediately possible, the following mitigations can reduce exposure: 1. Validate and limit the length of any user-controlled strings before passing them to shell-quote's `parse()` function. 2. If `parse()` is not required, ensure that only the `quote()` function is used, as it is not affected by this vulnerability. Workaround: You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component. Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce `pod-security.kubernetes.io/enforce: restricted`. Additionally, verify that the `pipeline-runner` ServiceAccount is not bound to `privileged` or `anyuid` Security Context Constraints (SCCs). Workaround: Configure Feast to enforce `auth.type: kubernetes` in the operator-generated configuration and deny registry writes by default. This measure limits the attack surface by requiring proper authentication and authorization for registry modifications, preventing the deserialization of malicious user-defined functions. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content …

🔗 References (148)