Red Hat OpenShift AI
18 known vulnerabilities in Red Hat OpenShift AI, 2 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-48710 CVSS 6.5 medium · actively exploited Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
Latest vulnerabilities
- CVE-2026-87743 CVSS 7.5 high A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the…
- CVE-2026-92091 CVSS 5.9 medium A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with…
- CVE-2026-86332 CVSS 6.5 medium A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads…
- CVE-2026-84185 CVSS 5.9 medium A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The…
- CVE-2026-18393 CVSS 5.4 medium A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted…
- CVE-2026-80179 CVSS 5.9 medium A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period…
- CVE-2026-16118 CVSS 7.1 high A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c…
- CVE-2026-48779 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to…
- CVE-2026-8643 CVSS 4.1 medium pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the…
- CVE-2026-48710 CVSS 6.5 medium · actively exploited Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-45736 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to…
- CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-42264 CVSS 9.1 critical Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties…
- CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
- CVE-2025-69873 CVSS 2.9 low ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is…
- CVE-2025-11065 CVSS 5.3 medium A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This…
- CVE-2026-23745 CVSS 8.2 high node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries…
- CVE-2025-6170 CVSS 2.5 low A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long…