RHSA-2026:73987CriticalCVSS 9.3

Red Hat Security Advisory: RHOAI 3.3.7 - Red Hat OpenShift AI

Published
September 30, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (125)

CVE-2026-31958 →CVE-2025-71408 →CVE-2026-28500 →CVE-2026-28684 →CVE-2026-59869 →CVE-2026-81722 →CVE-2026-5422 →CVE-2026-12151 →CVE-2026-27136 →CVE-2026-39832 →CVE-2026-49855 →CVE-2026-11824 →CVE-2026-39821 →CVE-2026-44432 →CVE-2026-45736 →CVE-2026-48746 →CVE-2026-56853 →CVE-2026-56859 →CVE-2026-33816 →CVE-2026-44431 →CVE-2026-48586 →CVE-2026-67322 →CVE-2026-66040 →CVE-2026-6321 →CVE-2026-34986 →CVE-2026-39830 →CVE-2026-54058 →CVE-2026-59197 →CVE-2026-64834 →CVE-2026-32274 →CVE-2026-33811 →CVE-2026-53550 →CVE-2026-59204 →CVE-2026-73089 →CVE-2026-69192 →CVE-2026-16221 →CVE-2026-27489 →CVE-2026-32597 →CVE-2026-48526 →CVE-2026-59886 →CVE-2026-69244 →CVE-2026-80205 →CVE-2026-84375 →CVE-2026-41242 →CVE-2026-54283 →CVE-2026-15378 →CVE-2026-28356 →CVE-2026-32286 →CVE-2026-81727 →CVE-2026-35397 →CVE-2026-44727 →CVE-2026-71281 →CVE-2026-33815 →CVE-2026-39828 →CVE-2026-44843 →CVE-2026-56858 →CVE-2026-73415 →CVE-2026-79674 →CVE-2026-59199 →CVE-2026-69152 →CVE-2026-66036 →CVE-2026-16745 →CVE-2026-18951 →CVE-2026-46595 →CVE-2026-59884 →CVE-2026-66037 →CVE-2026-69243 →CVE-2026-23490 →CVE-2026-35536 →CVE-2026-59874 →CVE-2026-68770 →CVE-2026-11822 →CVE-2026-40110 →CVE-2026-42294 →CVE-2026-56862 →CVE-2026-59205 →CVE-2026-79675 →CVE-2026-2229 →CVE-2026-13149 →CVE-2026-27893 →CVE-2026-33186 →CVE-2026-33814 →CVE-2026-34445 →CVE-2026-39835 →CVE-2026-42297 →CVE-2026-67323 →CVE-2026-11816 →CVE-2026-34993 →CVE-2026-42338 →CVE-2026-48779 →CVE-2026-55969 →CVE-2026-63310 →CVE-2026-64835 →CVE-2025-66471 →CVE-2026-9697 →CVE-2026-31230 →CVE-2026-39831 →CVE-2026-59873 →CVE-2026-25681 →CVE-2026-48710 →CVE-2026-62384 →CVE-2026-73627 →CVE-2026-78682 →CVE-2026-84445 →CVE-2026-1528 →CVE-2026-42502 →CVE-2026-1526 →CVE-2026-42508 →CVE-2026-56860 →CVE-2026-15154 →CVE-2025-61726 →CVE-2026-59885 →CVE-2026-6734 →CVE-2026-39829 →CVE-2026-42215 →CVE-2026-42296 →CVE-2026-59200 →CVE-2026-81724 →CVE-2026-33231 →CVE-2026-33245 →CVE-2026-44240 →CVE-2026-66038 →CVE-2026-67325 →CVE-2026-73417 →CVE-2026-1525 →

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-71408 — nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module CVE-2026-1525 — undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers CVE-2026-1526 — undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression CVE-2026-1528 — undici: undici: Denial of Service via crafted WebSocket frame with large length CVE-2026-2229 — undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter CVE-2026-5422 — jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-11816 — keras: Keras: Arbitrary file write via path traversal in archive extraction utilities CVE-2026-11822 — sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data CVE-2026-11824 — sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-15154 — guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex CVE-2026-15378 — guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:) CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-16745 — odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation CVE-2026-18951 — odh-training-operator-rhel9: [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27489 — onnx: ONNX: Information Disclosure via Path Traversal Vulnerability CVE-2026-27893 — vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting CVE-2026-28356 — multipart: denial of service via maliciously crafted HTTP or multipart segment headers CVE-2026-28500 — onnx: ONNX: Untrusted Model Repository Warnings Suppressed CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following CVE-2026-31230 — adversarial-robustness-toolbox: Adversarial Robustness Toolbox: Arbitrary Code Execution via Command-Line Argument Injection CVE-2026-31958 — tornado-python: Tornado: Denial of Service via large multipart bodies CVE-2026-32274 — black: Black: Arbitrary file writes from unsanitized user input in cache file name CVE-2026-32286 — github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation) CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33231 — nltk: NLTK: Denial of Service via unauthenticated remote shutdown CVE-2026-33245 — react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-34445 — ONNX: ONNX: Denial of Service and potential information disclosure via malicious model metadata CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-35397 — jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability CVE-2026-35536 — tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-40110 — jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation CVE-2026-41242 — protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42294 — Argo Workflows: github.com/argoproj/argo-workflows: Argo Workflows: Denial of Service via large request body to Webhook Interceptor CVE-2026-42296 — Argo Workflows: github.com/argoproj/argo-workflows: Argo Workflows: Privilege escalation via security control bypass CVE-2026-42297 — Argo Workflows: github.com/argoproj/argo-workflows: Argo Workflows: Unauthorized ConfigMap manipulation due to missing authorization CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44240 — basic-ftp: basic-ftp: Client-side Denial of Service via unterminated multiline FTP responses CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44727 — jupyter-server: Jupyter Server: Remote Code Execution via stored Cross-Site Scripting in nbconvert handlers CVE-2026-44843 — langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments CVE-2026-49855 — tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption CVE-2026-53550 — js-yaml: js-yaml: Denial of Service via crafted YAML merge keys CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header CVE-2026-59884 — python-pyasn1: pyasn1: Denial of Service via crafted BER input CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-62384 — nltk: NLTK: Information Disclosure via Symlink Sandbox Bypass CVE-2026-63310 — nltk: NLTK before 3.9.3 Missing Post-Download Integrity Verification CVE-2026-64834 — FFmpeg: Denial of Service via crafted RTP/ASF stream CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files CVE-2026-66036 — ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter CVE-2026-66037 — FFmpeg: FFmpeg: Denial of Service via uncontrolled resource consumption in IAMF demuxer CVE-2026-66038 — FFmpeg: Information disclosure via malformed zlib video stream CVE-2026-66040 — ffmpeg: FFmpeg: Arbitrary code execution via crafted PNG image CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-68770 — sentence-transformers: sentence-transformers: Remote Code Execution via Security Control Bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71281 — peft: peft: Arbitrary Code Execution via Unsafe Deserialization in LoRA-GA and CorDA Modules CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73415 — jupyterlab: JupyterLab: Arbitrary code execution via malicious image in image viewer CVE-2026-73417 — jupyterlab: JupyterLab: Cross-site scripting (XSS) allows arbitrary code execution CVE-2026-73627 — jupyterlab: JupyterLab: Plugin manager lock-rule bypass allows unauthorized plugin control CVE-2026-78682 — nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration CVE-2026-79674 — nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors CVE-2026-79675 — nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options CVE-2026-80205 — nltk: NLTK: Denial of Service via unvalidated regular expressions CVE-2026-81722 — nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing CVE-2026-81724 — nltk: NLTK: Denial of Service via Uncontrolled Recursion CVE-2026-81727 — nltk: NLTK: Filesystem containment bypass allows local file overwrite CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests

🎯 Affected products200

  • Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:6a3e7d0dcb52e8ea9e4f73344ff216b880dadf61f03a0551b7e97fe383098368_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:a99728acf3903cde208545be44c734eea2568ab85e85e1f42c7b44b34e99280c_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:bf08b9713fb677f4b3605c29ac85fcabc4d41d085b605306c21ae1be4edfb510_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:dab9ae66c726e3aee041f5366806f52b2d49636a5d5784ed7d6b6d7bd62215d1_s390x as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-cli-rhel9@sha256:4a9a56bf874d62f966c4b1710098cab4b1f08b4f861be784f188ed546b79b028_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-cli-rhel9@sha256:9149f42ed8d222d0761d76ec6c2196c6cf06d6fb800ca3f21eadb8930424573b_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-cli-rhel9@sha256:e72318a5214fb85fa39e2fddb7aa982121444241137a073e31bed9b96c6cd6d1_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:34be19a6a0bc7ad5c47f85d4f0b676df88211d0687e5ff3853c8b9e901e6d542_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:397b15d36564af99170b2aaa57c7012d130b4d5bc45f1e2e80891329bf6f3944_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c0bb08d3dea2add89b39261feac7775ca35b26cd294f8ae7f8dc02c4967676f9_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:d2dd5f64c3c111ff3f2b094d281a79a11e5f936c2b2995bc2026fc24671ed723_s390x as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:07bc3a8b5e7917ff635d98a096a045aa97948706dbe689d971fbb4c2a1ab5194_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:e4a14cbff68b92f52061f422fd5574b531c1faac84bf0af7ff115c9d603f01f8_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:f80e5470a30f091bd1903062b972a90176833784c7f00335580cf3d63c1a3673_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:89b6cafe47fe5cf58cf575426a9fb4181a1f0f22401f338af08fa80e78f22108_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:e70a0c2e31077b8451c30c6b24b4364dda3c732c2743eb30723aedf657836d27_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9@sha256:f678f7f10c33dd89e5ad5e88874ec8e124b57dab4c7eb3e7a929431628e477af_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:ca5399f87b15beef70cd7288db5f459f64d01c3bbd52898c1f8af850ca2bf2c7_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:d4b1d67e2404b143f5a0802df87153ccd226b0c34442d922dafa1eae0d5b1a4b_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-data-science-pipelines-operator-controller-rhel9@sha256:f5cdd9a6edcc3638fed8ebf152f77964f145faadb8cb2556bfe5f8815a2573a2_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:5f92b1f3080a302ee22a8f2bde96dfb5254da72b644c13d3a01bb16ddceb83fb_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:96696f4b960d08d301acf59d7892e2dec33cfb5f6fd3ec837b14ecc6106aa701_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:c01951fd6e025896b42009cbf593718acb5f38877b795e5a82b69e84515337bb_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:0851b1a60ca730cc3f90987786b2417ff5e8af538c29b844f6570773d10f6c09_ppc64le as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:74266732f0c2bb9aa5780f335d455b56f3c07dcd88371ac1af8ccce9a86b0396_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-feature-server-rhel9@sha256:8b5292b6c75adc97657b5dcf0ac6e9792cd90c7d39b35fd2feaaf3512d90786d_amd64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:1854e2d2b448e2c5cba1df6d9a03a6d8929a772257f589d16607edbc056497b6_s390x as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:311604924a40f24853ee375345d579424de157ef0fb0ffe5856c51fa15e3ac43_arm64 as a component of Red Hat OpenShift AI 3.3
  • registry.redhat.io/rhoai/odh-fms-guardrails-orchestrator-rhel9@sha256:405be4e78910c569005bc0f192ef0685751218b637c4b3f1fa513967704b5d16_amd64 as a component of Red Hat OpenShift AI 3.3
  • +170 more not shown

✅ Remediation

For Red Hat OpenShift AI 3.3.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, avoid directly invoking the `nltk.collocations` module's internal script (`collocations.py`) with untrusted command-line arguments. In standard Red Hat deployments, NLTK is typically used as an imported library, which does not expose this vulnerability. If direct invocation is necessary, ensure that all command-line arguments are from trusted sources and are properly validated. Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: To mitigate this issue, avoid extracting archives from untrusted sources. When archive extraction is necessary, ensure that the operation is performed within a dedicated, restricted directory by explicitly changing the current working directory to a non-root, isolated location before extraction. This limits the potential impact of arbitrary file writes. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Administrators should review and adjust their Kubernetes RBAC configurations within Red Hat OpenShift AI to ensure that `trainjobs` permissions are explicitly managed. This involves removing `trainjobs` from the `aggregate-to-edit` ClusterRole labels or requiring explicit `RoleBinding` for `trainjobs` access. This prevents implicit permission grants to namespace editors and reduces the attack surface. Consult Kubernetes documentation for specific instructions on modifying ClusterRoles and RoleBindings. A restart or reload of affected components may be required for changes to take effect. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: To mitigate this vulnerability, ensure that only trusted and authorized users have permissions to create, modify, or deploy Kubeflow pipelines and configurations within Red Hat OpenShift AI. Restricting access to the environment where the Adversarial Robustness Toolbox (ART) evaluation scripts are executed can prevent attackers from controlling the vulnerable command-line arguments. If a service is restarted or reloaded, these access controls will persist. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, ensure that the NLTK WordNet Browser HTTP server (`nltk.app.wordnet_app`) is not exposed to untrusted networks. If the WordNet Browser functionality is not required, disable or remove the component. For deployments where the server is necessary, configure firewall rules to restrict access to trusted hosts only. A service restart may be required for changes to take effect. Workaround: To mitigate this Cross-Site Scripting (XSS) vulnerability, ensure that applications utilizing React Router's unstable React Server Components (RSC) APIs only process redirects from trusted sources. Avoiding the use of these unstable APIs in production environments where untrusted redirect sources cannot be guaranteed is also recommended. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this issue, ensure that directory names within Jupyter Server deployments do not share common prefixes with sibling directories. This operational control prevents authenticated users from exploiting the path traversal vulnerability to access unauthorized content. For example, avoid naming directories 'user1' and 'user10' if 'user' is a common prefix. This mitigation does not require service restarts or reloads. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Administrators should review and update the `allow_origin_pat` configuration in Jupyter Server to use a more precise regular expression. Ensure the pattern explicitly anchors to the end of the string (e.g., by adding `$` to the end of the regex) to prevent partial domain matches. After modifying the configuration, the Jupyter Server service must be restarted for the changes to take effect. Workaround: Upgrade Argo Workflows to version 3.7.14 or later (3.x line) or 4.0.5 or later (4.x line) in affected Red Hat OpenShift AI releases. Red Hat OpenShift AI engineering is expected to deliver updated Data Science Pipelines builds for affected streams (rhoai-2.25, rhoai-3.3, rhoai-3.4). Until updated images are available, restrict network access to the Argo Server webhook endpoint (/api/v1/events/) using Ingress rules, firewall policies, …

🔗 References (130)