Red hat openshift ai (rhoai)
This hub aggregates every CVE we track for Red hat openshift ai (rhoai), a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
40
CVEs tracked
4
Critical
18
High
0
In CISA KEV
Severity distribution
HIGH18MEDIUM17CRITICAL4LOW1
Monthly trend
0
0
0
0
1
0
0
1
1
0
1
0
1
0
0
2
1
2
2
0
6
6
11
4
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat openshift ai (rhoai).
- CVE-2026-87743Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus http security7.5
- CVE-2026-92091Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array5.9
- CVE-2026-86332Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user6.5
- CVE-2026-84185Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification5.9
- CVE-2026-18393Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor5.4
- CVE-2026-80179Jwcrypto: jwcrypto: denial of service via malformed jwe tokens5.9
- CVE-2026-15218Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts with excessive permissions lead to privilege escalation7.9
- CVE-2026-18950Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creation8.8
- CVE-2026-18949Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources8.8
- CVE-2026-18948Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server9.9
- CVE-2026-18947Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized full re-materialization8.5
- CVE-2026-18942Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation5.5
- CVE-2026-18941Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authentication7.7
- CVE-2026-14450Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication9.9
- CVE-2026-13717Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: all allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)8.8
Product normalization is registry-driven with AI assist and human review. How it works