Red Hat
AI Threat Alert tracks 27 known AI/ML vulnerabilities affecting Red Hat products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every Red Hat CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| MEDIUM | CVE-2024-11831 | serialize-javascript: XSS via regex in AI/ML dashboards | odh-kf-notebook-controller-rhel8 | 5.4 |
| HIGH | CVE-2026-4424 | libarchive: RAR heap OOB read leaks memory in vLLM stacks | rhaiis/vllm-cuda-rhel9 | 7.5 |
| HIGH | CVE-2026-5121 | libarchive: integer overflow in zisofs hits vllm containers | rhaiis/vllm-cuda-rhel9 | 7.5 |
| HIGH | CVE-2023-52356 | libtiff: heap overflow DoS in vLLM inference via TIFF input | rhaiis/vllm-cuda-rhel9 | 7.5 |
| MEDIUM | CVE-2025-14831 | GnuTLS: TLS cert parsing DoS hits vllm inference | rhaiis/vllm-cuda-rhel9 | 5.3 |
| HIGH | CVE-2026-4111 | libarchive: infinite loop DoS in RAR5 decompression | rhaiis/vllm-cuda-rhel9 | 7.5 |
| HIGH | CVE-2026-5201 | gdk-pixbuf: JPEG heap overflow crashes vLLM inference | rhaiis/vllm-cuda-rhel9 | 7.5 |
| HIGH | CVE-2026-9064 | 389-ds-base: LDAP DoS via unbounded control count | 7.5 | |
| MEDIUM | CVE-2026-12491 | vLLM: image metadata mishandling corrupts multimodal inputs | rhaiis/vllm-cpu-rhel9 | 4.8 |
| MEDIUM | CVE-2026-12706 | FFmpeg RASC: UAF in decoder crashes AI inference containers | rhoai/odh-vllm-gaudi-rhel9 | 6.5 |
| HIGH | CVE-2025-9900 | libtiff: arbitrary write via crafted TIFF image | rhaiis/vllm-cuda-rhel9 | 8.8 |
| HIGH | CVE-2025-5318 | libssh: OOB read in SFTP handle leaks memory | rhaiis/vllm-cuda-rhel9 | 8.1 |
| HIGH | CVE-2026-10118 | Poppler: PDF integer overflow enables heap RCE | rhaiis/vllm-spyre-rhel9 | 7.8 |
| HIGH | CVE-2026-4775 | libtiff: integer overflow causes heap OOB write | rhaiis/vllm-spyre-rhel9 | 7.8 |
| MEDIUM | CVE-2026-4878 | libcap: TOCTOU race in cap_set_file() enables privesc | rhaiis/vllm-spyre-rhel9 | 6.7 |
| HIGH | CVE-2026-23536 | Feast: unauth path traversal leaks any file | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | 7.5 |
| CRITICAL | CVE-2026-23537 | Feast: unauth file write to RCE via /save-document | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | 9.1 |
| HIGH | CVE-2026-56208 | libaom: heap overflow in AV1 encoder LAP mode | rhaiis/vllm-cpu-rhel9 | 7.6 |
| HIGH | CVE-2026-56210 | libaom: AV1 SVC bounds-check miss leaks heap, crashes | rhaiis/vllm-cpu-rhel9 | 7.1 |
| HIGH | CVE-2026-56211 | libaom: AV1 SVC OOB write enables RCE | rhaiis/vllm-cpu-rhel9 | 7.1 |
Page 1 of 2
Frequently asked questions
How many known vulnerabilities affect Red Hat?
27 AI/ML CVEs affecting Red Hat products are tracked, sourced from NVD and GitHub Advisory.
What Red Hat products are affected?
The CVEs below map to the Red Hat AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the Red Hat vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor Red Hat for new vulnerabilities?
AI Threat Alert tracks Red Hat continuously; a Pro subscription adds breaking alerts when new CVEs affecting Red Hat are published.
How do I assess Red Hat's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity Red Hat issues first and judge the exposure for your stack.