Red Hat Openshift Ai
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Openshift Ai.
Recent Red Hat Openshift Ai Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:73987 | (RHSA-2026:73987) RHOAI 3.3.7 - Red Hat OpenShift AI | September 30, 2026 |
| RHSA-2026:53263 | (RHSA-2026:53263) RHOAI 3.3.6 - Red Hat OpenShift AI | August 11, 2026 |
| RHSA-2026:53262 | (RHSA-2026:53262) RHOAI 3.4.3 - Red Hat OpenShift AI | August 11, 2026 |
| RHSA-2026:53261 | (RHSA-2026:53261) RHOAI 2.25.10 - Red Hat OpenShift AI | August 11, 2026 |
| RHSA-2026:42644 | (RHSA-2026:42644) RHOAI 2.25.9 - Red Hat OpenShift AI | July 21, 2026 |
| RHSA-2026:37275 | (RHSA-2026:37275) RHOAI 3.3.5 - Red Hat OpenShift AI | July 9, 2026 |
| RHSA-2026:34456 | (RHSA-2026:34456) RHOAI 3.4.2 - Red Hat OpenShift AI | July 1, 2026 |
| RHSA-2026:30056 | (RHSA-2026:30056) RHOAI 3.3.4 - Red Hat OpenShift AI | June 25, 2026 |
| RHSA-2026:28960 | (RHSA-2026:28960) RHOAI 2.25.8 - Red Hat OpenShift AI | June 24, 2026 |
| RHSA-2026:27784 | (RHSA-2026:27784) RHOAI 3.4.1 - Red Hat OpenShift AI | June 22, 2026 |
By the Year
In 2026 there have been 350 vulnerabilities in Red Hat Openshift Ai with an average score of 7.7 out of ten. Last year, in 2025 Openshift Ai had 11 security vulnerabilities published. That is, 339 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 2.02.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 350 | 7.74 |
| 2025 | 11 | 5.72 |
| 2024 | 3 | 7.90 |
It may take a day or so for new Openshift Ai vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Openshift Ai Security Vulnerabilities
Quarkus HTTP Security Authorization Bypass via Path Normalization Discrepancy
CVE-2026-87743
7.5 - High
- September 18, 2026
A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the security matcher considers public, but which is then routed to a protected endpoint, leading to an authorization bypass and potential unauthorized access to sensitive information.
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
Redis Community Cluster Bus OOB Read via Unchecked Null-Termination
CVE-2026-92925
7.1 - High
- September 17, 2026
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Out-of-bounds Read
jwcrypto JWK.import_key() DoS via unbounded key_ops array
CVE-2026-92091
5.9 - Medium
- September 16, 2026
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply a JWK with a large key_ops array to an application that passes attacker-controlled key material to a public key-import API (reachable via ECDH-ES key agreement, OIDC dynamic client registration, DPoP, or ACME account key registration, among others) to consume excessive CPU time, resulting in a denial of service.
Inefficient Algorithmic Complexity
Red Hat OpenShift AI odh-dashboard: Unchecked K8s Secret read via BFF
CVE-2026-86332
6.5 - Medium
- September 07, 2026
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
AuthZ
jwcrypto General JWS Verification Bypass via Key ID Misidentification
CVE-2026-84185
5.9 - Medium
- September 03, 2026
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
Improper Verification of Cryptographic Signature
FFmpeg TDSC Cursor Heap Overflow in tdsc_load_cursor()
CVE-2026-18393
5.4 - Medium
- August 28, 2026
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.
Memory Corruption
jwcrypto JWE Deserialization Memory Overrun DoS
CVE-2026-80179
5.9 - Medium
- August 27, 2026
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.
Allocation of Resources Without Limits or Throttling
Risky OpenShift AI ServiceAccounts Grant Cluster-Admin Privileges
CVE-2026-15218
7.9 - High
- August 17, 2026
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.
Incorrect Privilege Assignment
Unauthorized SA Elevation in Red Hat Data Science Pipelines
CVE-2026-18620
7.1 - High
- August 10, 2026
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods.
Insecure Direct Object Reference / IDOR
ml-metadata HTTP/2 DoS via Outdated gRPC
CVE-2026-18618
7.5 - High
- August 10, 2026
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.
Allocation of Resources Without Limits or Throttling
Unauth Data Science Pipelines Operator: Weak PRNG Exposes MariaDB/MinIO Creds
CVE-2026-18611
7.5 - High
- August 10, 2026
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a cryptographically weak pseudo-random number generator (PRNG) to generate these credentials, making them predictable. Successful exploitation could lead to unauthorized access to all pipeline artifacts and metadata, resulting in significant information disclosure.
PRNG
RHOAI Training-Operator: Privilege Escalation in K8s
CVE-2026-18982
8.8 - High
- August 10, 2026
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough.
Execution with Unnecessary Privileges
RHOAI Overlay Causing Privilege Escalation via Edit ClusterRole
CVE-2026-18951
8.8 - High
- August 10, 2026
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution.
Privilege Defined With Unsafe Actions
CVE-2026-18950: ODH Dashboard Privilege Escalation via RoleBinding Manipulation
CVE-2026-18950
8.8 - High
- August 10, 2026
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system.
Incorrect Privilege Assignment
Privilege Escalation via Overly Broad SA Permissions in odhdashboard
CVE-2026-18949
8.8 - High
- August 10, 2026
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
Execution with Unnecessary Privileges
Unauthenticated Code Exec via UDF Deserialization in Feast (Python)
CVE-2026-18948
9.9 - Critical
- August 10, 2026
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.
Marshaling, Unmarshaling
Feast /materialize Auth Bypass Enables DoS
CVE-2026-18947
8.5 - High
- August 10, 2026
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The consequence is a Denial of Service (DoS) due to data corruption and significant resource consumption across all tenants.
AuthZ
Privilege Escalation via Code Injection in Feast Operator
CVE-2026-18942
5.5 - Medium
- August 10, 2026
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.
Code Injection
Feast Default no_auth Enables Unauth RCE, DoS, Data Leakage
CVE-2026-18941
7.7 - High
- August 10, 2026
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.
Missing Authentication for Critical Function
Red Hat Data Science Pipelines: API Bypass Grants Node-Root (CVE-2026-18621)
CVE-2026-18621
7.6 - High
- August 10, 2026
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Incorrect Privilege Assignment
Red Hat DSPO: Dangerous Spec.Database Params Enable Local INFILE PrivEsc
CVE-2026-18617
8.8 - High
- August 10, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable LOCAL INFILE functionality and exfiltrate sensitive files, such as the service account token, from the operator pod. This can lead to privilege escalation, allowing a namespace editor to gain cluster-admin privileges.
Mass Assignment
Red Hat DSPO ClusterRole Excess Privileges -> K8s Admin Access
CVE-2026-18608
8.7 - High
- August 10, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these privileges to gain full administrative control over the entire Kubernetes cluster.
Execution with Unnecessary Privileges
ODH Model-Controller LoadSecret Namespace Leak
CVE-2026-16456
6.5 - Medium
- August 10, 2026
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.
Confused Deputy
TrustyAI TAS Auth Bypass: Pods Bypass API Auth
CVE-2026-15581
8 - High
- August 10, 2026
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
Missing Authentication for Critical Function
Red Hat TrustyAI Service Operator LMEvalJob Sidecar Injection CVE-2026-15467
CVE-2026-15467
8.1 - High
- August 10, 2026
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Incorrect Privilege Assignment
Privilege Escalation via Header Injection in Red Hat MaaS API
CVE-2026-14450
9.9 - Critical
- August 10, 2026
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive model access configuration.
Authentication Bypass by Spoofing
RHOAI MaaS Gateway: Improper Config Lets Low-Privilege Users Intercept Data
CVE-2026-13717
8.8 - High
- August 10, 2026
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
Authorization
Auth Bypass in Red Hat ODH-Dashboard via Network Binding
CVE-2026-16745
8.8 - High
- July 23, 2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Origin Validation Error
GLib GDBus gdbusauth DoS via Input Length Misvalidation
CVE-2026-15588
5.3 - Medium
- July 20, 2026
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Allocation of Resources Without Limits or Throttling
XDGMIME Heap Buffer Overflow via MIME Magic File (CVE-2026-16118)
CVE-2026-16118
7.1 - High
- July 17, 2026
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Heap-based Buffer Overflow
Feast Feature Server /ws/chat WS Auth Bypass Enables DOS
CVE-2026-23538
7.5 - High
- July 16, 2026
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resourcessuch as memory, CPU, and file descriptorsleading to a complete denial of service for legitimate users.
Allocation of Resources Without Limits or Throttling
vllm-orchestrator-gateway PII Leak: Logs Auth Headers & Chat Payloads
CVE-2026-15574
7.5 - High
- July 13, 2026
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.
Insertion of Sensitive Information into Externally-Accessible File or Directory
XSD Injection in guardrails-detectors File_Type Detector Enables SSRF & LFI
CVE-2026-15143
9.3 - Critical
- July 10, 2026
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.
SSRF
Red Hat guardrails-detectors SSRF via crafted XSD blind request
CVE-2026-15378
9.3 - Critical
- July 10, 2026
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
SSRF
ReDoS in guardrails-detectors (Red Hat OpenShift AI)
CVE-2026-15154
6.5 - Medium
- July 08, 2026
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.
ReDoS
Unauthorized Access via Unproxied Metrics in TrustYai Gorch Service
CVE-2026-15063
6.3 - Medium
- July 08, 2026
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.
Missing Authentication for Critical Function
CVE-2026-15044: TrustyAI Service Operator Allows Unauthorized Cluster Access
CVE-2026-15044
6.3 - Medium
- July 08, 2026
A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.
Information Disclosure
Unauthenticated FS Write via /save-document in Feast Feature Server
CVE-2026-23537
9.1 - Critical
- July 01, 2026
A vulnerability has been identified in the Feast Feature Servers `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the server can potentially compromise the integrity of the system. This could lead to unauthorized system modifications, denial of service through disk exhaustion, or potential remote code execution.
AuthZ
GLib g_dbus_node_info_new_for_xml uint overflow OOB read DoS
CVE-2026-58016
7.5 - High
- June 30, 2026
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Integer underflow
GLib D-Bus DBUS_COOKIE_SHA1 Auth: CookieCtx Path Traversal CVE-2026-58015
CVE-2026-58015
5.9 - Medium
- June 30, 2026
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Directory traversal
GLib g_key_file Off-By-One Array Index Bug Causing OOB Access
CVE-2026-58014
7.3 - High
- June 30, 2026
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
off-by-five
GLib Buffer Over-Read in giochannel.c Minor Info Disclosure & DoS
CVE-2026-58013
6.5 - Medium
- June 30, 2026
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
Buffer Over-read
GLib g_regex_replace over-read via G_REGEX_RAW causing info leak & DoS
CVE-2026-58012
6.5 - Medium
- June 30, 2026
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
Buffer Over-read
GLib Off-by-One in gvs_tuple_is_normal leads to 1byte OOB Read
CVE-2026-58010
6.5 - Medium
- June 30, 2026
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
Buffer Over-read
Out-of-bounds read in GLib g_date_time_get_ymd
CVE-2026-58011
6.5 - Medium
- June 30, 2026
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
Out-of-bounds Read
Double-Free in libarchive RAR5 Reader
CVE-2026-14164
7.5 - High
- June 30, 2026
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.
Double-free
Heap-based Buffer Overflow in libtiff PixarLog Decoder
CVE-2026-12912
7.3 - High
- June 29, 2026
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Heap-based Buffer Overflow
fast-uri <=3.1.2/4.0.0 Unicode IDN Canonicalization Bug
CVE-2026-13676
7.5 - High
- June 29, 2026
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.
Interpretation Conflict
FFmpeg RASC Decoder OOB Heap Write via Malformed Frame
CVE-2026-58049
7.6 - High
- June 28, 2026
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.
Memory Corruption
docling <2.91.0 Zip Slip in EasyOCR model download
CVE-2026-44017
8.3 - High
- June 24, 2026
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP archives without validating member paths, enabling Zip Slip attacks. If an attacker could compromise the model download source (via supply chain attack, DNS spoofing, or MITM), they could write arbitrary files to any location writable by the process, potentially achieving remote code execution by overwriting Python files or system binaries, persistent backdoors by modifying startup scripts or SSH keys, and data corruption or system compromise. This vulnerability is fixed in 2.91.0.
Directory traversal
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Openshift Ai or by Red Hat? Click the Watch button to subscribe.