Junglewise Threat Intelligence

CVE-2026-15574: Red Hat OpenShift AI sensitive information disclosure in vllm-orchestrator-gateway logs

CVE-2026-15574 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Red Hat.

Executive brief

A security flaw was found in the vLLM orchestrator gateway, a component used in AI platforms to manage large language model traffic. The system incorrectly records sensitive information, including user passwords, security tokens, and private chat conversations, into system logs. Anyone with permission to view system logs can access this data, potentially leading to identity theft or the exposure of confidential business information.

Technical details

A vulnerability exists in the vllm-orchestrator-gateway component where the production binary is hard-coded to initialize tracing at the DEBUG level. This causes the application to log all incoming 'Authorization' headers (including Bearer tokens) and full chat payloads (containing PII or secrets) to stdout. In environments like OpenShift, these logs are forwarded to the node journal and cluster logging stack. An attacker or unauthorized user with 'pods/log' RBAC permissions can harvest these credentials and sensitive conversation data. The root cause is the unconditional use of 'tracing::Level::DEBUG' in 'src/main.rs' without proper redaction of sensitive fields.

Affected products

  • Red Hat Red Hat OpenShift AI (RHOAI) unspecified

Timeline

  • 2026-07-13: advisory: NVD and Red Hat published the advisory.

References