Red hat openshift ai (rhoai)
This hub aggregates every CVE we track for Red hat openshift ai (rhoai), a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
28
CVEs tracked
3
Critical
12
High
0
In CISA KEV
Severity distribution
HIGH12MEDIUM12CRITICAL3LOW1
Monthly trend
0
0
0
0
0
1
0
0
1
1
0
1
0
1
0
0
2
1
2
2
0
6
9
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat openshift ai (rhoai).
- CVE-2026-16745Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation8.8
- CVE-2026-23538Feast: resource exhaustion via websocket endpoint7.5
- CVE-2026-15574Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default7.5
- CVE-2026-15143Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)9.3
- CVE-2026-15378Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)9.3
- CVE-2026-15154Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex6.5
- CVE-2026-15063Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled6.3
- CVE-2026-15044Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis6.3
- CVE-2026-23537Feast: unauthenticated arbitrary file write9.1
- CVE-2026-56211Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames7.1
- CVE-2026-56210Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id7.1
- CVE-2026-56209Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack7.1
- CVE-2026-56208Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode7.6
- CVE-2026-12706Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()6.5
- CVE-2026-12491Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations4.8
Product normalization is registry-driven with AI assist and human review. How it works