Red Hat Security Advisory: RHOAI 3.4.4 - Red Hat OpenShift AI
🔗 CVE IDs covered (143)
📋 Description
CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data
CVE-2025-66626 — github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links
CVE-2025-71329 — image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field
CVE-2025-71330 — image-size: image-size: Denial of Service via crafted ICNS image buffer
CVE-2026-0545 — mlflow/mlflow: mlflow/mlflow: Unauthenticated remote code execution via unprotected job endpoints
CVE-2026-2614 — mlflow: mlflow: Arbitrary file read via bypassed source path validation
CVE-2026-5241 — python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
CVE-2026-5422 — jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-12243 — nltk: NLTK: Information disclosure via path traversal vulnerability
CVE-2026-12481 — keras: Keras: Arbitrary code execution via deserialization vulnerability
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-13311 — shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-13717 — RHOAI MaaS: llm-d: MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)
CVE-2026-14450 — maas-billing: MaaS API: Privilege escalation via forged HTTP headers due to missing authentication
CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex
CVE-2026-15218 — models-as-a-service: Red Hat OpenShift AI: maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation
CVE-2026-15378 — guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:)
CVE-2026-15467 — trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override
CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation
CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide
CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials
CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod
CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy
CVE-2026-18621 — data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening
CVE-2026-18948 — feast: Feast: Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server
CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole
CVE-2026-18982 — odh-training-operator-rhel9: RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
CVE-2026-33079 — mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input
CVE-2026-33245 — react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()
CVE-2026-35397 — jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-40171 — Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
CVE-2026-41672 — xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection
CVE-2026-41673 — @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents
CVE-2026-41675 — xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions
CVE-2026-42211 — react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation
CVE-2026-42266 — jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-42305 — dulwich: Dulwich: Remote Code Execution via Malicious Git Repository
CVE-2026-42311 — Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42342 — react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-42557 — jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
CVE-2026-44017 — docling: Docling: Remote code execution via Zip Slip vulnerability in model download
CVE-2026-44018 — docling: Docling: Denial of Service via crafted document archives
CVE-2026-44020 — docling: Docling: Information disclosure via XML External Entity (XXE) vulnerability
CVE-2026-44240 — basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-44289 — protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding
CVE-2026-44290 — protobufjs: protobufjs: Denial of Service via crafted schema
CVE-2026-44291 — protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution
CVE-2026-44292 — protobufjs: protobufjs: Data integrity impact due to prototype pollution
CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-44513 — Diffusers: Diffusers: Arbitrary remote code execution via trust_remote_code bypass
CVE-2026-44660 — python-ujson: UltraJSON: Memory leak leading to Denial of Service
CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape
CVE-2026-44724 — systeminformation: systeminformation: Command injection via NetworkManager connection profile name
CVE-2026-44727 — jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers
CVE-2026-44827 — diffusers: Diffusers: Arbitrary Code Execution via malicious model loading
CVE-2026-44843 — langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization
CVE-2026-45292 — opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-45740 — protobufjs: protobufjs: Denial of Service via crafted JSON descriptors
CVE-2026-45804 — diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-46625 — js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution
CVE-2026-47214 — docling: Docling: Unsafe URI and Path Handling in HTML Backend
CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header
CVE-2026-48712 — protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability
CVE-2026-49476 — python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string
CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
CVE-2026-49851 — Mistune: Mistune: Denial of Service via crafted Markdown input
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
CVE-2026-50193 — jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
CVE-2026-53550 — js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
CVE-2026-54293 — nltk: NLTK: Information Disclosure via Path Traversal in nltk.data.load()
CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file
CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
CVE-2026-55685 — react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests
CVE-2026-56121 — feast: Feast: Remote Code Execution via Unsafe Deserialization in gRPC Registry Server
CVE-2026-56208 — libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode
CVE-2026-56209 — libaom: libaom: arbitrary address write via SVC layer context OOB and cyclic refresh map pointer hijack
CVE-2026-56210 — libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
CVE-2026-56211 — libaom: libaom: remote code execution via SVC layer context handling with attacker-controlled frames
CVE-2026-58049 — FFmpeg: FFmpeg: Memory corruption via crafted RASC video stream
CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write
CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream
CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image
CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb
CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
CVE-2026-59884 — python-pyasn1: pyasn1: Denial of Service via crafted BER input
CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files
CVE-2026-64849 — mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade
CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
🎯 Affected products200
- Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:170e78670297c1c9435cff22c3f227edd58dc30993ebd0cb3d8265de838210af_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:2f83d14f149aa832849e346b90fb4449ba3511bb56108cfeebe295b627c1cb80_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:5cb9fb802c5439bd68d14df430144da061675fdd70f1b38a07284e0e5c8b3894_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:617d5a2b3008ad195f6f26692ff9a8ee6ebb2a940b39b7245916af517b130a90_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:11140a858c6fd3174d63e845f7d0bd451e67d50adc3befbfac57659d6334dfef_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:2d169d86c2e33636fbfce62d08d85e266bde276a7ea24ea205e921a9633e3008_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:81087b35bd99aff8fc8db0918bc613b96e4d9a3eafff3a27078185c06412b6d1_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:b49858f38add2b26168ac0437524cf9829cbbc4812e4fcd1347915da2df3afb8_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:719e138a13ad9cfaff20cb03295538c85dda4fc051ff866b25e04f1be8456ea4_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:8404758b6b7609b6728f3d464560221bb0250e82406ec879cfcb50819e19f201_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:9a5f6e83add8f4ec9f41284ee9c1a689cb193c1be7bd3860256bb612355e2631_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:c7b9ca039c7ed15d23bd819cb6d6f45748cf2f86f7096ebc2db31b1d0f3c1e70_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:3037ef27d81723dbe3ca98bf55c5c93fff42f3fad5935559cbf6eb272778ed7f_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:b017469cbd901503271b8944df40a74cf408c5223a880c696448f2b098b7c112_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:bddfb02d685a2511cbf83bf8c6fba7872864b411adcb06d272bbfda89882883a_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:e7d23a7fa4026469af734196cc0f56d5fdadd79eb5d04bb77c152019356ab679_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:07f8ee936a6fc58fb75dd487034dbe308db6c2a566c340922aefba4bd66c7c92_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:db345b46ed71b50223ee62c58a1a70198e2d728fca81550a81a932d5d7e718f6_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c7daef8e89de0e096983b72e81eeae966cea075874f1ddc498e0f92b9d5a278d_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:dbaf78b7927d84af5cb0839937541970959ad7c22238e0ba1128eaf7605968b2_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f3ee104a6bda47b1fd75494d5cde518327d39a5b1e3db2353e3103a77d75baf0_s390x as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5b32f727afed4fe60f0c1f53d05bc0345e2b02c55c9882de10cb376366686461_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:775c307e1cfb3f68cfc081aafc9d968ace5ff88b5407e4365bb46d9ab7fcf609_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:9fa5ec6f9e81cb122f732887a065272bcd98448180923be0024c541bee75b7e1_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:6838e7e122464c2a2afbc1ec7294c6bea54a59110cfcd090e17e462aa99050e7_amd64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c8bcf379905652e7822492d03f18cbac2e92421055a6f760b8a3ec1ec712b6a1_ppc64le as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:c9ccf4e8a33568b7dcc701f59d51b913607424bf95e8b51709911cf3e690db51_arm64 as a component of Red Hat OpenShift AI 3.4
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:201cc48366e9650b4524b83352e72289bf62235a7ab9aa2903eb4ebee2ae83ee_arm64 as a component of Red Hat OpenShift AI 3.4
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Upgrade to a version of image-size that validates box size fields. As a workaround, validate image inputs before passing them to image-size, rejecting files with zero-length box entries. Workaround: Upgrade to a version of image-size that validates ICNS entry length fields. As a workaround, validate image inputs before passing them to image-size, rejecting ICNS files with zero-length entries. Workaround: To mitigate this issue, disable job execution on the MLflow server by setting the `MLFLOW_SERVER_ENABLE_JOB_EXECUTION` environment variable to `false`. This prevents unauthenticated access to job endpoints. Example: `MLFLOW_SERVER_ENABLE_JOB_EXECUTION=false mlflow server` If configured as a service, update the service definition to include this environment variable. A restart of the MLflow server is required for the change to take effect. Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Do not pass untrusted or user-controlled input directly to nltk.data.load() or nltk.data.find(). Validate and sanitize any resource name parameter before use, rejecting values containing percent-encoded characters (%2f, %2e) or path traversal sequences. As defense-in-depth, set nltk.pathsec.ENFORCE = True in application code to enable file-read restrictions at the open stage (disabled by default). Workaround: To reduce exposure, only deserialize Keras models from trusted sources. When deserializing models, explicitly enable `safe_mode` by wrapping the deserialization call within a `SafeModeScope(True)` context. This ensures the deserialization safeguard is enforced, preventing the execution of arbitrary code. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Upgrade shell-quote to version 1.8.5. If upgrading shell-quote to version 1.8.5 or later is not immediately possible, the following mitigations can reduce exposure: 1. Validate and limit the length of any user-controlled strings before passing them to shell-quote's `parse()` function. 2. If `parse()` is not required, ensure that only the `quote()` function is used, as it is not affected by this vulnerability. Workaround: You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component. Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce `pod-security.kubernetes.io/enforce: restricted`. Additionally, verify that the `pipeline-runner` ServiceAccount is not bound to `privileged` or `anyuid` Security Context Constraints (SCCs). Workaround: Configure Feast to enforce `auth.type: kubernetes` in the operator-generated configuration and deny registry writes by default. This measure limits the attack surface by requiring proper authentication and authorization for registry modifications, preventing the deserialization of malicious user-defined functions. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content …
🔗 References (148)
- selfhttps://access.redhat.com/errata/RHSA-2026:60520
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2025-66626
- externalhttps://access.redhat.com/security/cve/CVE-2025-71329
- externalhttps://access.redhat.com/security/cve/CVE-2025-71330
- externalhttps://access.redhat.com/security/cve/CVE-2026-0545
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-12151
- externalhttps://access.redhat.com/security/cve/CVE-2026-12243
- externalhttps://access.redhat.com/security/cve/CVE-2026-12481
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13311
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-13717
- externalhttps://access.redhat.com/security/cve/CVE-2026-14450
- externalhttps://access.redhat.com/security/cve/CVE-2026-15154
- externalhttps://access.redhat.com/security/cve/CVE-2026-15218
- externalhttps://access.redhat.com/security/cve/CVE-2026-15378
- externalhttps://access.redhat.com/security/cve/CVE-2026-15467
- externalhttps://access.redhat.com/security/cve/CVE-2026-15581
- externalhttps://access.redhat.com/security/cve/CVE-2026-16745
- externalhttps://access.redhat.com/security/cve/CVE-2026-18608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18611
- externalhttps://access.redhat.com/security/cve/CVE-2026-18617
- externalhttps://access.redhat.com/security/cve/CVE-2026-18620
- externalhttps://access.redhat.com/security/cve/CVE-2026-18621
- externalhttps://access.redhat.com/security/cve/CVE-2026-18948
- externalhttps://access.redhat.com/security/cve/CVE-2026-18951
- externalhttps://access.redhat.com/security/cve/CVE-2026-18982
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-2614
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-33079
- externalhttps://access.redhat.com/security/cve/CVE-2026-33245
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-34993
- externalhttps://access.redhat.com/security/cve/CVE-2026-35397
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-40171
- externalhttps://access.redhat.com/security/cve/CVE-2026-41672
- externalhttps://access.redhat.com/security/cve/CVE-2026-41673
- externalhttps://access.redhat.com/security/cve/CVE-2026-41675
- externalhttps://access.redhat.com/security/cve/CVE-2026-42211
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42264
- externalhttps://access.redhat.com/security/cve/CVE-2026-42266
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-42305
- externalhttps://access.redhat.com/security/cve/CVE-2026-42311
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-42342
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-42557
- externalhttps://access.redhat.com/security/cve/CVE-2026-44017
- externalhttps://access.redhat.com/security/cve/CVE-2026-44018
- externalhttps://access.redhat.com/security/cve/CVE-2026-44020
- externalhttps://access.redhat.com/security/cve/CVE-2026-44240
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-44289
- externalhttps://access.redhat.com/security/cve/CVE-2026-44290
- externalhttps://access.redhat.com/security/cve/CVE-2026-44291
- externalhttps://access.redhat.com/security/cve/CVE-2026-44292
- externalhttps://access.redhat.com/security/cve/CVE-2026-44293
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-44513
- externalhttps://access.redhat.com/security/cve/CVE-2026-44660
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-44724
- externalhttps://access.redhat.com/security/cve/CVE-2026-44727
- externalhttps://access.redhat.com/security/cve/CVE-2026-44827
- externalhttps://access.redhat.com/security/cve/CVE-2026-44843
- externalhttps://access.redhat.com/security/cve/CVE-2026-45292
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-45740
- externalhttps://access.redhat.com/security/cve/CVE-2026-45804
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-46625
- externalhttps://access.redhat.com/security/cve/CVE-2026-47214
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-48710
- externalhttps://access.redhat.com/security/cve/CVE-2026-48712
- externalhttps://access.redhat.com/security/cve/CVE-2026-48779
- externalhttps://access.redhat.com/security/cve/CVE-2026-48801
- externalhttps://access.redhat.com/security/cve/CVE-2026-49476
- externalhttps://access.redhat.com/security/cve/CVE-2026-49477
- externalhttps://access.redhat.com/security/cve/CVE-2026-49851
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-50193
- externalhttps://access.redhat.com/security/cve/CVE-2026-5241
- externalhttps://access.redhat.com/security/cve/CVE-2026-53550
- externalhttps://access.redhat.com/security/cve/CVE-2026-54058
- externalhttps://access.redhat.com/security/cve/CVE-2026-54060
- externalhttps://access.redhat.com/security/cve/CVE-2026-5422
- externalhttps://access.redhat.com/security/cve/CVE-2026-54283
- externalhttps://access.redhat.com/security/cve/CVE-2026-54293
- externalhttps://access.redhat.com/security/cve/CVE-2026-55379
- externalhttps://access.redhat.com/security/cve/CVE-2026-55380
- externalhttps://access.redhat.com/security/cve/CVE-2026-55685
- externalhttps://access.redhat.com/security/cve/CVE-2026-56121
- externalhttps://access.redhat.com/security/cve/CVE-2026-56208
- externalhttps://access.redhat.com/security/cve/CVE-2026-56209
- externalhttps://access.redhat.com/security/cve/CVE-2026-56210
- externalhttps://access.redhat.com/security/cve/CVE-2026-56211
- externalhttps://access.redhat.com/security/cve/CVE-2026-58049
- externalhttps://access.redhat.com/security/cve/CVE-2026-59197
- externalhttps://access.redhat.com/security/cve/CVE-2026-59199
- externalhttps://access.redhat.com/security/cve/CVE-2026-59200
- externalhttps://access.redhat.com/security/cve/CVE-2026-59204
- externalhttps://access.redhat.com/security/cve/CVE-2026-59205
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/cve/CVE-2026-59884
- externalhttps://access.redhat.com/security/cve/CVE-2026-59885
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-64835
- externalhttps://access.redhat.com/security/cve/CVE-2026-64849
- externalhttps://access.redhat.com/security/cve/CVE-2026-6734
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-69243
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/cve/CVE-2026-9697
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/solutions/7145755
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60520.json