Red Hat
AI Threat Alert tracks 40 known AI/ML vulnerabilities affecting Red Hat products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every Red Hat CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| HIGH | CVE-2026-56209 | libaom: arbitrary address write in AV1 SVC codec | rhaiis/vllm-cpu-rhel9 | 7.1 |
| HIGH | CVE-2026-42010 | gnutls: NUL-byte username bypasses RSA-PSK auth | rhaiis/vllm-rocm-rhel9 | 7.1 |
| HIGH | CVE-2026-33846 | GnuTLS: DTLS fragment heap overflow, DoS on AI inference | rhaiis/vllm-rocm-rhel9 | 7.5 |
| HIGH | CVE-2026-42009 | gnutls: DTLS packet-reorder bug DoS hits AI inference servers | rhaiis/vllm-rocm-rhel9 | 7.5 |
| HIGH | CVE-2026-33845 | GnuTLS: DTLS integer underflow enables OOB read/DoS | rhaiis/vllm-rocm-rhel9 | 7.5 |
| HIGH | CVE-2026-23538 | Feast: unauth WebSocket connections cause DoS | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | 7.5 |
| HIGH | CVE-2023-52355 | libtiff: OOM DoS in vLLM inference container images | rhaiis/vllm-cuda-rhel9 | 7.5 |
| MEDIUM | CVE-2024-1023 | Vert.x: memory leak in HTTP client enables DoS | 6.5 | |
| MEDIUM | CVE-2024-1726 | Quarkus RESTEasy: DoS via late-stage auth checks | 5.3 | |
| HIGH | CVE-2026-18621 | OpenShift AI Pipelines: confused deputy grants node-root | rhaiis/vllm-cpu-rhel9 | 7.6 |
| HIGH | CVE-2026-18947 | Feast: authz bypass in /materialize triggers DoS | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | 8.5 |
| MEDIUM | CVE-2026-18942 | Feast operator: code injection escalates to cluster admin | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | 5.5 |
| CRITICAL | CVE-2026-18948 | Feast: insecure UDF deserialization enables RCE | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | 9.9 |
| HIGH | CVE-2026-18941 | Feast: no-auth default enables RCE via malicious UDF | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | 7.7 |
| HIGH | CVE-2026-18949 | ODH Dashboard: SA token abuse escalates to cluster-admin | rhoai/odh-mod-arch-mlflow-rhel9 | 8.8 |
| HIGH | CVE-2026-18950 | odh-dashboard: unvalidated roleRef enables cluster-admin | rhoai/odh-mod-arch-mlflow-rhel9 | 8.8 |
| MEDIUM | CVE-2026-18663 | 389-ds-base: double-free in LDAP control handling | 5.9 | |
| MEDIUM | CVE-2026-18393 | FFmpeg: heap overflow via crafted TDSC cursor in video | rhoai/odh-vllm-gaudi-rhel9 | 5.4 |
| MEDIUM | CVE-2026-86332 | RHOAI dashboard: broken authz leaks NIM/NGC secrets | rhoai/odh-mod-arch-mlflow-rhel9 | 6.5 |
| HIGH | CVE-2026-92925 | rhaii/vllm-rocm-rhel9 | 7.1 |
Page 2 of 2
Frequently asked questions
How many known vulnerabilities affect Red Hat?
40 AI/ML CVEs affecting Red Hat products are tracked, sourced from NVD and GitHub Advisory.
What Red Hat products are affected?
The CVEs below map to the Red Hat AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the Red Hat vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor Red Hat for new vulnerabilities?
AI Threat Alert tracks Red Hat continuously; a Pro subscription adds breaking alerts when new CVEs affecting Red Hat are published.
How do I assess Red Hat's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity Red Hat issues first and judge the exposure for your stack.