Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI
🔗 CVE IDs covered (117)
📋 Description
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
CVE-2025-67030 — org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method
CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-9563 — org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-12243 — nltk: NLTK: Information disclosure via path traversal vulnerability
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-15075 — vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects
CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex
CVE-2026-15378 — guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:)
CVE-2026-15581 — trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation
CVE-2026-18608 — data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org /, and ClusterRole/Binding CRUD cluster-wide
CVE-2026-18611 — data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials
CVE-2026-18617 — data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod
CVE-2026-18620 — data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy
CVE-2026-18621 — data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
CVE-2026-33231 — nltk: NLTK: Denial of Service via unauthenticated remote shutdown
CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values
CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
CVE-2026-34445 — ONNX: ONNX: Denial of Service and potential information disclosure via malicious model metadata
CVE-2026-35536 — tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-40171 — Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42027 — Apache OpenNLP: Apache OpenNLP: Arbitrary Class Loading via Model Manifest
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-42579 — netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
CVE-2026-42583 — netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
CVE-2026-44240 — basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
CVE-2026-44893 — netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
CVE-2026-45112 — thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
CVE-2026-45416 — netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-45674 — netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling
CVE-2026-47691 — io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-48043 — netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
CVE-2026-48059 — netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
CVE-2026-50010 — netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
CVE-2026-50193 — jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
CVE-2026-53550 — js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
CVE-2026-54293 — nltk: NLTK: Information Disclosure via Path Traversal in nltk.data.load()
CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVE-2026-55685 — react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests
CVE-2026-55831 — io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing
CVE-2026-55833 — netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification
CVE-2026-55851 — io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message
CVE-2026-56745 — netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec
CVE-2026-56746 — io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header
CVE-2026-56819 — io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb
CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
CVE-2026-59899 — io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
CVE-2026-66036 — ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter
CVE-2026-66039 — ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file
CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON
CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter
CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL
CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
CVE-2026-67324 — gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass
CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation
CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser
CVE-2026-69112 — accelerate: Hugging Face Accelerate: Path Traversal and Denial of Service via weight_map
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade
CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
CVE-2026-71281 — peft: peft: Arbitrary Code Execution via Unsafe Deserialization in LoRA-GA and CorDA Modules
CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service
CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results
CVE-2026-73415 — jupyterlab: JupyterLab: Arbitrary code execution via malicious image in image viewer
CVE-2026-73417 — jupyterlab: JupyterLab: Cross-site scripting (XSS) allows arbitrary code execution
CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-73627 — jupyterlab: JupyterLab: Plugin manager lock-rule bypass allows unauthorized plugin control
CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products200
- Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:098f5e28dfc097b69748be2d9fdd392a4bf03b8c43ce2c049bbb60c87f66ab68_s390x as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:89cdb5783188b1b594cd7e0c6da1993397d60fe706e3469c331693f38c168b4d_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:bbae57467b7801ead9ce5c3d4cd2c65857d460ff5e585608f3419646f700afbc_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:c041b82ea051a3ad476720c6e12c8ba16e5ad49576dd363713ab543732b4a513_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:06578a9cb2dbaeae1423d49978f6589a41935603aabc14d0164913b5ade19a41_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-nlp-rhel9@sha256:526197d0ec19250946cde2639a21578955b30be8f1b9cea6e23e7c8ed3e86869_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:308080b253a1935f47fd758a182588b77543b95740f94a4fcd491dd451d04ced_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:addf2f0bea155f9fe30785c0cf8adb9205f726ee5d0cf3c1d3ade2c1cbea40f2_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:045e0c83d6df54e862add0f28a5f65b10049f275c8843d093d190ea42e8b509c_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:254e1b0470712b30ff1dc320662a315c0de1be7cebb9bed2172011231c11eae3_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:09c0f607f8dad58b125ca04a1dc81f12b2756c23804215e7a7e6661c8cfdd57e_s390x as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3268e27af4f4af4c20ba2ff049a9551feba44907e8398183aa6db5b8c304b7de_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:91c876725560656458d2b3571fb59e6b055ca9a23b16dcf87260769f7de71c55_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:acf4fc094f9b45178b4a1ebed8ca64d17b065bd7e7a74b945e0866bed1180d48_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:413aea240bb48927895d5a224f414207e7df46d9a7172e248660136a5f4b775b_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:8eae9b630b66b4265022a1899df60ae1276d51d778b331b98e2bbbc967b2efe6_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:c372f38c39164b68f7eb26b4d78a8ac162a57b183552522b94060e87993715b0_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:520837d415654b6bd3d5d2f724d3b26dffffc965b76ffa2868837b68951cdc26_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:57c0859b44499c16a49f12c15c5bd234c8beccea5f2bf82afbda03ec1b4bc3dc_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:d3b819909db3897c2a411c18254df205f44c6aa54e83a2c9058e33120f44787f_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:6f77fcdf0e5f77c142c3695875a636fa51b338f422c01eb76f525825bc9eee63_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:e0d085c660c39b702db988fc8822b913da8a801525c0fd5896de174a15213c7c_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:e910488975b28286d1e38ead00be371fcc0a678e9f1246e2db9f70d41dbeabc7_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:cfd4f68626c051f392ba3f3e75a8a82ad3debb49c20c4984e4ac859365b15e35_arm64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:db3e21a5dffea34329a93c4bfe34031cc92cca9c76d880fd50ad2bda1983a1cc_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:ea67fceb10f623a608c3dd56df32fe566f82a578715ae7d4f9ef9810f2ca3ab4_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:5ff076f464e3184bf6a4aa5f3fa28442d9063a1e7c96c985b352142392f90f6b_amd64 as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:9159665d9fd67ec03f5c3051f953b6a599dcdc34dc26f79284da90b1c3d7cb4a_ppc64le as a component of Red Hat OpenShift AI 2.25
- registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:d3b7c6ff33c190c83fb9f6b5eb0f9105a0e1600202f56f9da460b671c37620f8_arm64 as a component of Red Hat OpenShift AI 2.25
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 2.25.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, limit the use of multiple sequential optional groups in route patterns within applications that use `path-to-regexp`. Additionally, avoid directly passing user-controlled input as route patterns to prevent the generation of maliciously crafted regular expressions. Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Do not pass untrusted or user-controlled input directly to nltk.data.load() or nltk.data.find(). Validate and sanitize any resource name parameter before use, rejecting values containing percent-encoded characters (%2f, %2e) or path traversal sequences. As defense-in-depth, set nltk.pathsec.ENFORCE = True in application code to enable file-read restrictions at the open stage (disabled by default). Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this issue, configure applications utilizing Vert.x HttpClient to strictly validate and restrict the URLs to which HTTP requests can be redirected. Implement allowlists for trusted domains and ensure that any user-supplied or external URLs processed by Vert.x HttpClient are thoroughly sanitized and validated to prevent redirection to attacker-controlled destinations. This may involve updating application-specific configurations or implementing custom URL validation logic. A service restart or reload may be required for changes to take effect. Workaround: To reduce the attack surface, administrators should review and modify the `ClusterRole` associated with the Data Science Pipelines Operator (DSPO) to remove unnecessary permissions. Specifically, restrict or remove permissions for `pods/exec`, `kubeflow.org */*`, `seldondeployments *`, and broad `apiGroups:'*'` for deployments and services. The operator's `ClusterRole` should be limited to only the required resources such as `apps/deployments`, `services`, `secrets`, `configmaps`, `roles/rolebindings`, `routes`, `networkpolicies`, `servicemonitors`, and DSPA/Argo CRDs. Applying these changes may require restarting the DSPO pod for the updated permissions to take effect and could impact operator functionality if not carefully validated. Workaround: To mitigate this issue, users should explicitly provide strong, cryptographically secure credentials for MariaDB and MinIO when deploying the Data Science Pipelines Operator. Additionally, restrict network access to the MinIO and MariaDB services using OpenShift NetworkPolicies to limit exposure. Avoid exposing MinIO via public OpenShift Routes unless absolutely necessary and ensure MariaDB is not configured with an empty root password. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, operators of Red Hat OpenShift AI should configure an allow-list for ServiceAccounts that tenants can specify in their workflow run requests. Restricting the available ServiceAccounts to a predefined, least-privileged set, such as the default `pipeline-runner` only, will prevent unauthorized privilege escalation. This configuration change should be applied to the API server responsible for processing workflow run requests. New workflow runs will respect the updated configuration. Workaround: To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce `pod-security.kubernetes.io/enforce: restricted`. Additionally, verify that the `pipeline-runner` ServiceAccount is not bound to `privileged` or `anyuid` Security Context Constraints (SCCs). Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: To mitigate this vulnerability, ensure that the NLTK WordNet Browser HTTP server (`nltk.app.wordnet_app`) is not exposed to untrusted networks. If the WordNet Browser functionality is not required, disable or remove the component. For deployments where the server is necessary, configure firewall rules to restrict access to trusted hosts only. A service restart may be required for changes to take effect. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To reduce the risk of exploitation, disable the affected help extensions in Jupyter Notebook and JupyterLab, or set the `allowCommandLinker` option to `false` within the sanitizer configuration. Consult the Jupyter documentation for specific instructions on modifying these settings. Disabling these features may affect the availability of certain help functionalities. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: To mitigate this issue, restrict applications using the `basic-ftp` client to …
🔗 References (121)
- selfhttps://access.redhat.com/errata/RHSA-2026:65126
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-67030
- externalhttps://access.redhat.com/security/cve/CVE-2026-12151
- externalhttps://access.redhat.com/security/cve/CVE-2026-12243
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-15075
- externalhttps://access.redhat.com/security/cve/CVE-2026-15154
- externalhttps://access.redhat.com/security/cve/CVE-2026-15378
- externalhttps://access.redhat.com/security/cve/CVE-2026-15581
- externalhttps://access.redhat.com/security/cve/CVE-2026-16745
- externalhttps://access.redhat.com/security/cve/CVE-2026-18608
- externalhttps://access.redhat.com/security/cve/CVE-2026-18611
- externalhttps://access.redhat.com/security/cve/CVE-2026-18617
- externalhttps://access.redhat.com/security/cve/CVE-2026-18620
- externalhttps://access.redhat.com/security/cve/CVE-2026-18621
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27904
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-33231
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-33870
- externalhttps://access.redhat.com/security/cve/CVE-2026-33871
- externalhttps://access.redhat.com/security/cve/CVE-2026-34445
- externalhttps://access.redhat.com/security/cve/CVE-2026-35536
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-40171
- externalhttps://access.redhat.com/security/cve/CVE-2026-40192
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42027
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-42578
- externalhttps://access.redhat.com/security/cve/CVE-2026-42579
- externalhttps://access.redhat.com/security/cve/CVE-2026-42581
- externalhttps://access.redhat.com/security/cve/CVE-2026-42583
- externalhttps://access.redhat.com/security/cve/CVE-2026-42584
- externalhttps://access.redhat.com/security/cve/CVE-2026-42587
- externalhttps://access.redhat.com/security/cve/CVE-2026-44240
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-44249
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44893
- externalhttps://access.redhat.com/security/cve/CVE-2026-45112
- externalhttps://access.redhat.com/security/cve/CVE-2026-45416
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-45674
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-45819
- externalhttps://access.redhat.com/security/cve/CVE-2026-47691
- externalhttps://access.redhat.com/security/cve/CVE-2026-48043
- externalhttps://access.redhat.com/security/cve/CVE-2026-48059
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-48779
- externalhttps://access.redhat.com/security/cve/CVE-2026-4926
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-50010
- externalhttps://access.redhat.com/security/cve/CVE-2026-50193
- externalhttps://access.redhat.com/security/cve/CVE-2026-53550
- externalhttps://access.redhat.com/security/cve/CVE-2026-54293
- externalhttps://access.redhat.com/security/cve/CVE-2026-54512
- externalhttps://access.redhat.com/security/cve/CVE-2026-55685
- externalhttps://access.redhat.com/security/cve/CVE-2026-55831
- externalhttps://access.redhat.com/security/cve/CVE-2026-55833
- externalhttps://access.redhat.com/security/cve/CVE-2026-55851
- externalhttps://access.redhat.com/security/cve/CVE-2026-56745
- externalhttps://access.redhat.com/security/cve/CVE-2026-56746
- externalhttps://access.redhat.com/security/cve/CVE-2026-56819
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/cve/CVE-2026-59885
- externalhttps://access.redhat.com/security/cve/CVE-2026-59899
- externalhttps://access.redhat.com/security/cve/CVE-2026-66036
- externalhttps://access.redhat.com/security/cve/CVE-2026-66039
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67322
- externalhttps://access.redhat.com/security/cve/CVE-2026-67323
- externalhttps://access.redhat.com/security/cve/CVE-2026-67324
- externalhttps://access.redhat.com/security/cve/CVE-2026-67325
- externalhttps://access.redhat.com/security/cve/CVE-2026-6734
- externalhttps://access.redhat.com/security/cve/CVE-2026-68494
- externalhttps://access.redhat.com/security/cve/CVE-2026-69112
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-69243
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/cve/CVE-2026-71281
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-73415
- externalhttps://access.redhat.com/security/cve/CVE-2026-73417
- externalhttps://access.redhat.com/security/cve/CVE-2026-73566
- externalhttps://access.redhat.com/security/cve/CVE-2026-73622
- externalhttps://access.redhat.com/security/cve/CVE-2026-73623
- externalhttps://access.redhat.com/security/cve/CVE-2026-73624
- externalhttps://access.redhat.com/security/cve/CVE-2026-73625
- externalhttps://access.redhat.com/security/cve/CVE-2026-73627
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/cve/CVE-2026-9563
- externalhttps://access.redhat.com/security/cve/CVE-2026-9697
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65126.json