Red Hat Security Advisory: RHOAI 3.5.1 - Red Hat OpenShift AI
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-19913 — mwEmbed: html5lib: Kaltura HTML5 Player: Information disclosure via improper validation of ServiceUrl parameter CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-62384 — nltk: NLTK: Information Disclosure via Symlink Sandbox Bypass CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names CVE-2026-79674 — nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors CVE-2026-80205 — nltk: NLTK: Denial of Service via unvalidated regular expressions CVE-2026-81722 — nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing CVE-2026-81724 — nltk: NLTK: Denial of Service via Uncontrolled Recursion CVE-2026-81727 — nltk: NLTK: Filesystem containment bypass allows local file overwrite
🎯 Affected products200
- Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-operator-rhel9@sha256:1c1ee6cf448d91226fffc32d478ad143c11e893a9841d9883f6ef6b267431e02_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-operator-rhel9@sha256:3acbd795ecccda803a44f0077595e9b9ca1720c61e0ef2b3594d32517618b4c6_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-operator-rhel9@sha256:7091f3e9e8e0841835fe5e22bd4b6a7276b84386519e001814eb814f190c1d9f_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-operator-rhel9@sha256:88eae8d5602c76fcd9297d45e534b08056aa2d4e6377e16e6da292e78e77496d_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:77711850ebc8ed6e516f4cbee195285a8c6b064b436540bb813928c38350abdc_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:8f1aa3baa5b0bd61316d196cc88b1a141ebd181850d1ba22aaff7ee5ad6f3f00_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:af86d2562adfb6a7c2e7ffc0b25191266148423f4b5a228288b6ed3a90431301_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-ai-gateway-payload-processing-rhel9@sha256:dbbc0ef187fd86399bd95b5a9c298d9598d0058782fa76d16a092cfcfceae54e_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:135b99ac3f7975337e8c207b3e82bacec78be446908065aa4d6144eaeae10264_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:2bd6ae8fd7647f7130d9513dca1204b568fb5aac3cde99bbbaa35551821c536d_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:2f3a228740f44ea74c349f620aa91c930da790b01b8de3631027181341dc9d12_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-automl-rhel9@sha256:75871bd88c994731d4a12554c0088401942e4ab801e4f9d353a1ed6671232226_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:27d0833efd8096d7311746c1a4f72699b945b2b2fa88ed47073eba96bb3b9503_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:33f21d285a066050aa45b10785a438caef3808b54d8ee7994e036be4601d5750_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:aeaa0d8311432347a632870d9baccb3face7d6bd61a48b9d15497640d8741e48_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-autorag-rhel9@sha256:e742c0cfcc7e78815e4b57afd49515d2afee7f71166f8d01986a2b6b6e207e14_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:3f9eb3befce443e8e9b188f75afd769cb818d43021629cdfe3eb3fd5ac5f4d9d_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:405ad2a86a3ff55426c7713b2c762be55da1ca51f1bdc90f23a107a788e84fd9_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:50285c800369ee473516a729cdeb4d418df730e88003272c11fb95ba9dbbe735_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:b714e1dabb874c521fc41542c9c7e653c070667dc6f11adca069aa365f1a6b01_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:44cc3a35b40cb14e3d84b97e8c2ccc0145f3f26fc9b2cf6acf1a8d4a33e0c6c4_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-cli-rhel9@sha256:5ffe015048c799624b8f154e8c5582327a24676b772b3138b2f00fb6d9d4fd3b_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-core-bff-rhel9@sha256:1ef9f3fecee851243909ebd07cf184d29d59e1fca6665fe997832e3e87ff11dd_s390x as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-core-bff-rhel9@sha256:9aa78e05d0c16cace4ace7de07bc07cb772403c60cd557b753fb980881646f66_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-core-bff-rhel9@sha256:e683d11de1a782b2a796c99eccb5dfb3b908e721210ba87c2e06768f1fa8745d_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-core-bff-rhel9@sha256:ee09233bcedde0e89182e1a47e66e82924e86389023fa717a33dc834f192f3cc_ppc64le as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-dashboard-operator-rhel9@sha256:0ba3a882e1ec7dd5b81c7defce0ee81d2699dd15e26c08d906498e3d796f3512_arm64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-dashboard-operator-rhel9@sha256:0f0a7c4386c958d30b1be5dcbec6a98ae5cabbdfb93570849991912cf318ae99_amd64 as a component of Red Hat OpenShift AI 3.5
- registry.redhat.io/rhoai/odh-dashboard-operator-rhel9@sha256:4cfa3e8a95932dbf08743abc491ff1470dbad8c5a2e0dcb9d812e167e21fb079_s390x as a component of Red Hat OpenShift AI 3.5
- +170 more not shown
✅ Remediation
For Red Hat OpenShift AI 3.5.1 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict write permissions on NLTK corpus subdirectories to prevent unauthorized symlink creation, or sanitize input paths to prevent FramenetCorpusReader from loading untrusted corpus files containing unresolved symbolic links. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Sanitize user input passed to `LinThesaurusCorpusReader` and `PanLexLiteCorpusReader` initialization arguments to enforce strict path validation against expected data root directories before loading corpus files or SQLite databases. Workaround: Sanitize all untrusted input passed to `Text.findall()` or `TokenSearcher.findall()` to prevent execution of arbitrary or unvalidated regular expressions, or enforce execution timeouts via worker process isolation to bound CPU consumption. Workaround: Applications that process untrusted feature-structure input using NLTK should implement robust input validation and sanitization to prevent deeply nested structures from being processed by `nltk.featstruct.FeatStructReader`. If input cannot be validated, avoid processing untrusted feature-structure input with affected versions of NLTK. Workaround: To mitigate this issue, ensure that NLTK downloader directories are not shared among untrusted users or are configured with restrictive permissions to prevent unauthorized write access. If a shared downloader directory is essential, implement strict access controls to limit write permissions to only trusted accounts. This reduces the attack surface by preventing malicious local users from creating hardlinks to arbitrary files.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2026:69539
- externalhttps://access.redhat.com/security/cve/CVE-2026-19913
- externalhttps://access.redhat.com/security/cve/CVE-2026-54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-59893
- externalhttps://access.redhat.com/security/cve/CVE-2026-62384
- externalhttps://access.redhat.com/security/cve/CVE-2026-69243
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/cve/CVE-2026-71491
- externalhttps://access.redhat.com/security/cve/CVE-2026-71556
- externalhttps://access.redhat.com/security/cve/CVE-2026-76222
- externalhttps://access.redhat.com/security/cve/CVE-2026-79674
- externalhttps://access.redhat.com/security/cve/CVE-2026-80205
- externalhttps://access.redhat.com/security/cve/CVE-2026-81722
- externalhttps://access.redhat.com/security/cve/CVE-2026-81724
- externalhttps://access.redhat.com/security/cve/CVE-2026-81727
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69539.json