{"schema_version":1,"title":"Red Hat OpenShift AI vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Red Hat OpenShift AI: 0 in the last 7 days and 2 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15154, was published on 8 July 2026.","url":"https://junglewise.ai/threats/technologies/openshift-ai-rhoai","json_url":"https://junglewise.ai/threats/technologies/openshift-ai-rhoai.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openshift-ai-rhoai","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":13,"critical":4,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":13},"latest":[{"cve":"CVE-2026-15154","cvss":6.5,"slug":"cve-2026-15154-red-hat-openshift-ai-redos-in-guardrails-detectors","title":"Red Hat OpenShift AI ReDoS in guardrails-detectors","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:48.43+00:00","url":"https://junglewise.ai/threats/cve-2026-15154-red-hat-openshift-ai-redos-in-guardrails-detectors"},{"cve":"CVE-2026-15044","cvss":6.3,"slug":"cve-2026-15044-red-hat-trustyai-service-operator-unauthenticated-access-in-ai","title":"Red Hat TrustyAI Service Operator unauthenticated access in AI APIs","severity":"medium","exploited":false,"published_at":"2026-07-08T15:16:26.12+00:00","url":"https://junglewise.ai/threats/cve-2026-15044-red-hat-trustyai-service-operator-unauthenticated-access-in-ai"},{"cve":"CVE-2026-31230","cvss":9.8,"epss":0.005,"slug":"cve-2026-31230-trusted-ai-adversarial-robustness-toolbox-code-injection-in","title":"Trusted-AI Adversarial Robustness Toolbox code injection in Kubeflow component","severity":"critical","exploited":false,"published_at":"2026-05-12T18:16:51.277+00:00","url":"https://junglewise.ai/threats/cve-2026-31230-trusted-ai-adversarial-robustness-toolbox-code-injection-in"},{"cve":"CVE-2026-6587","cvss":6.3,"epss":0.0037,"slug":"cve-2026-6587-vibrantlabsai-ragas-ssrf-in-collections-module","title":"vibrantlabsai RAGAS SSRF in Collections Module","severity":"medium","exploited":false,"published_at":"2026-04-20T00:16:34.703+00:00","url":"https://junglewise.ai/threats/cve-2026-6587-vibrantlabsai-ragas-ssrf-in-collections-module"},{"cve":"CVE-2025-15379","cvss":9.8,"epss":0.0236,"slug":"cve-2025-15379-mlflow-command-injection-in-model-serving-container","title":"MLflow command injection in model serving container initialization","severity":"critical","exploited":false,"published_at":"2026-03-30T08:16:15.667+00:00","url":"https://junglewise.ai/threats/cve-2025-15379-mlflow-command-injection-in-model-serving-container"},{"cve":"CVE-2025-15036","cvss":10,"epss":0.0058,"slug":"cve-2025-15036-mlflow-path-traversal-in-extract-archive-to-dir","title":"MLflow path traversal in extract_archive_to_dir","severity":"critical","exploited":false,"published_at":"2026-03-30T02:16:14.413+00:00","url":"https://junglewise.ai/threats/cve-2025-15036-mlflow-path-traversal-in-extract-archive-to-dir"},{"cve":"CVE-2025-15381","cvss":7.1,"epss":0.0033,"slug":"cve-2025-15381-mlflow-authorization-bypass-in-tracing-and-assessment-endpoints","title":"MLflow authorization bypass in tracing and assessment endpoints","severity":"high","exploited":false,"published_at":"2026-03-27T17:16:26.573+00:00","url":"https://junglewise.ai/threats/cve-2025-15381-mlflow-authorization-bypass-in-tracing-and-assessment-endpoints"},{"cve":"CVE-2026-23536","cvss":7.5,"epss":0.0066,"slug":"cve-2026-23536-feast-feature-server-path-traversal-in-read-document-endpoint","title":"Feast Feature Server path traversal in /read-document endpoint","severity":"high","exploited":false,"published_at":"2026-03-20T22:16:27.087+00:00","url":"https://junglewise.ai/threats/cve-2026-23536-feast-feature-server-path-traversal-in-read-document-endpoint"},{"cve":"CVE-2025-15031","cvss":9.1,"epss":0.0085,"slug":"cve-2025-15031-mlflow-path-traversal-in-pyfunc-extraction","title":"MLflow path traversal in pyfunc extraction","severity":"critical","exploited":false,"published_at":"2026-03-18T23:17:28.693+00:00","url":"https://junglewise.ai/threats/cve-2025-15031-mlflow-path-traversal-in-pyfunc-extraction"},{"cve":"CVE-2025-14287","cvss":8.8,"epss":0.0146,"slug":"cve-2025-14287-mlflow-command-injection-in-sagemaker-container-parameter","title":"MLflow command injection in SageMaker container parameter","severity":"high","exploited":false,"published_at":"2026-03-16T14:17:55.61+00:00","url":"https://junglewise.ai/threats/cve-2025-14287-mlflow-command-injection-in-sagemaker-container-parameter"},{"cve":"CVE-2026-2635","cvss":7.3,"epss":0.0122,"slug":"cve-2026-2635-mlflow-authentication-bypass-via-hard-coded-default-credentials","title":"MLflow authentication bypass via hard-coded default credentials","severity":"high","exploited":false,"published_at":"2026-02-20T23:16:05.577+00:00","url":"https://junglewise.ai/threats/cve-2026-2635-mlflow-authentication-bypass-via-hard-coded-default-credentials"},{"cve":"CVE-2026-1669","cvss":7.5,"epss":0.0031,"slug":"cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading","title":"Google Keras arbitrary file read in HDF5 model loading","severity":"high","exploited":false,"published_at":"2026-02-11T23:16:03.75+00:00","url":"https://junglewise.ai/threats/cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading"},{"cve":"CVE-2025-15514","cvss":7.5,"epss":0.0064,"slug":"cve-2025-15514-ollama-null-pointer-dereference-in-multi-modal-image-processing","title":"Ollama null pointer dereference in multi-modal image processing","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.957+00:00","url":"https://junglewise.ai/threats/cve-2025-15514-ollama-null-pointer-dereference-in-multi-modal-image-processing"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Keycloak","slug":"red-hat-keycloak","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/red-hat-keycloak"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Ansible Automation Platform","slug":"ansible-automation-platform-2","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/ansible-automation-platform-2"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"}],"technology":{"hub":true,"name":"Red Hat OpenShift AI","slug":"openshift-ai-rhoai","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"platform-as-a-service","homepage":"https://www.redhat.com/en/technologies/cloud-computing/openshift/openshift-ai","description":"Platform for building, training, and deploying machine learning models on OpenShift.","url":"https://junglewise.ai/threats/technologies/openshift-ai-rhoai"},"most_severe":[{"cve":"CVE-2025-15036","cvss":10,"epss":0.0058,"slug":"cve-2025-15036-mlflow-path-traversal-in-extract-archive-to-dir","title":"MLflow path traversal in extract_archive_to_dir","severity":"critical","exploited":false,"published_at":"2026-03-30T02:16:14.413+00:00","url":"https://junglewise.ai/threats/cve-2025-15036-mlflow-path-traversal-in-extract-archive-to-dir"},{"cve":"CVE-2025-15379","cvss":9.8,"epss":0.0236,"slug":"cve-2025-15379-mlflow-command-injection-in-model-serving-container","title":"MLflow command injection in model serving container initialization","severity":"critical","exploited":false,"published_at":"2026-03-30T08:16:15.667+00:00","url":"https://junglewise.ai/threats/cve-2025-15379-mlflow-command-injection-in-model-serving-container"},{"cve":"CVE-2026-31230","cvss":9.8,"epss":0.005,"slug":"cve-2026-31230-trusted-ai-adversarial-robustness-toolbox-code-injection-in","title":"Trusted-AI Adversarial Robustness Toolbox code injection in Kubeflow component","severity":"critical","exploited":false,"published_at":"2026-05-12T18:16:51.277+00:00","url":"https://junglewise.ai/threats/cve-2026-31230-trusted-ai-adversarial-robustness-toolbox-code-injection-in"},{"cve":"CVE-2025-15031","cvss":9.1,"epss":0.0085,"slug":"cve-2025-15031-mlflow-path-traversal-in-pyfunc-extraction","title":"MLflow path traversal in pyfunc extraction","severity":"critical","exploited":false,"published_at":"2026-03-18T23:17:28.693+00:00","url":"https://junglewise.ai/threats/cve-2025-15031-mlflow-path-traversal-in-pyfunc-extraction"},{"cve":"CVE-2025-14287","cvss":8.8,"epss":0.0146,"slug":"cve-2025-14287-mlflow-command-injection-in-sagemaker-container-parameter","title":"MLflow command injection in SageMaker container parameter","severity":"high","exploited":false,"published_at":"2026-03-16T14:17:55.61+00:00","url":"https://junglewise.ai/threats/cve-2025-14287-mlflow-command-injection-in-sagemaker-container-parameter"},{"cve":"CVE-2026-23536","cvss":7.5,"epss":0.0066,"slug":"cve-2026-23536-feast-feature-server-path-traversal-in-read-document-endpoint","title":"Feast Feature Server path traversal in /read-document endpoint","severity":"high","exploited":false,"published_at":"2026-03-20T22:16:27.087+00:00","url":"https://junglewise.ai/threats/cve-2026-23536-feast-feature-server-path-traversal-in-read-document-endpoint"},{"cve":"CVE-2025-15514","cvss":7.5,"epss":0.0064,"slug":"cve-2025-15514-ollama-null-pointer-dereference-in-multi-modal-image-processing","title":"Ollama null pointer dereference in multi-modal image processing","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.957+00:00","url":"https://junglewise.ai/threats/cve-2025-15514-ollama-null-pointer-dereference-in-multi-modal-image-processing"},{"cve":"CVE-2026-1669","cvss":7.5,"epss":0.0031,"slug":"cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading","title":"Google Keras arbitrary file read in HDF5 model loading","severity":"high","exploited":false,"published_at":"2026-02-11T23:16:03.75+00:00","url":"https://junglewise.ai/threats/cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading"},{"cve":"CVE-2026-2635","cvss":7.3,"epss":0.0122,"slug":"cve-2026-2635-mlflow-authentication-bypass-via-hard-coded-default-credentials","title":"MLflow authentication bypass via hard-coded default credentials","severity":"high","exploited":false,"published_at":"2026-02-20T23:16:05.577+00:00","url":"https://junglewise.ai/threats/cve-2026-2635-mlflow-authentication-bypass-via-hard-coded-default-credentials"},{"cve":"CVE-2025-15381","cvss":7.1,"epss":0.0033,"slug":"cve-2025-15381-mlflow-authorization-bypass-in-tracing-and-assessment-endpoints","title":"MLflow authorization bypass in tracing and assessment endpoints","severity":"high","exploited":false,"published_at":"2026-03-27T17:16:26.573+00:00","url":"https://junglewise.ai/threats/cve-2025-15381-mlflow-authorization-bypass-in-tracing-and-assessment-endpoints"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}