rhoai/odh-data-science-pipelines-operator-controller-rhel9 vulnerabilities
CVEs whose affected-version data names the rhoai/odh-data-science-pipelines-operator-controller-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-18611High· 7.5A flaw was found in the Data Science Pipelines Operator
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinI…
CVE-2026-18608High· 8.7A flaw was found in the Data Science Pipelines Operator (DSPO)
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…
CVE-2026-18617High· 8.8A flaw was found in the Data Science Pipelines Operator (DSPO)
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…