rhoai/odh-latency-predictor-prediction-rhel9 vulnerabilities
CVEs whose affected-version data names the rhoai/odh-latency-predictor-prediction-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-18618High· 7.5A flaw was found in ml-metadata
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit…
CVE-2026-15467High· 8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the us…
CVE-2026-18982High· 8.8A flaw was found in the RHOAI training-operator
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can imperson…
CVE-2026-18951High· 8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with …
CVE-2026-18620High· 7.1A flaw was found in Data Science Pipelines
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…
CVE-2026-18611High· 7.5A flaw was found in the Data Science Pipelines Operator
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinI…
CVE-2026-15581High· 8.0A flaw was found in the TrustyAI Service (TAS) deployment
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or d…
CVE-2026-18608High· 8.7A flaw was found in the Data Science Pipelines Operator (DSPO)
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…
CVE-2026-18617High· 8.8A flaw was found in the Data Science Pipelines Operator (DSPO)
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…