rhoai/odh-ml-pipelines-api-server-v2-rhel9 vulnerabilities
CVEs whose affected-version data names the rhoai/odh-ml-pipelines-api-server-v2-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-18620High· 7.1A flaw was found in Data Science Pipelines
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…
▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.48%via NVD
CVE-2026-18621High· 7.6A flaw was found in Data Science Pipelines (DSP)
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with …
▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.51%via NVD