VulnSea

rhoai/odh-latency-predictor-prediction-rhel9 vulnerabilities

CVEs whose affected-version data names the rhoai/odh-latency-predictor-prediction-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-18618High· 7.5
1mo ago

A flaw was found in ml-metadata

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit…

▾ TwilightRed Hat · rhoai/odh-mlmd-grpc-server-rhel9EPSS 0.83%via NVD
CVE-2026-15467High· 8.1
1mo ago

A flaw was found in the trustyai-service-operator's LMEvalJob controller

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the us…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.60%via NVD
CVE-2026-18982High· 8.8
1mo ago

A flaw was found in the RHOAI training-operator

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can imperson…

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.79%via NVD
CVE-2026-18951High· 8.8
1mo ago

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with …

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.89%via NVD
CVE-2026-18620High· 7.1
1mo ago

A flaw was found in Data Science Pipelines

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.48%via NVD
CVE-2026-18611High· 7.5
1mo ago

A flaw was found in the Data Science Pipelines Operator

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinI…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.61%via NVD
CVE-2026-15581High· 8.0
1mo ago

A flaw was found in the TrustyAI Service (TAS) deployment

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or d…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.42%via NVD
CVE-2026-18608High· 8.7
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.70%via NVD
CVE-2026-18617High· 8.8
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.73%via NVD
rhoai/odh-latency-predictor-prediction-rhel9 vulnerabilities (CVEs) · VulnSea