CVE-2026-15143 – Red Hat OpenShift AI (RHOAI)
“When internal services become reachable from the outside, sensitive data is only one request away.”
Red Hat has released security updates for Red Hat OpenShift AI (RHOAI) to address two Critical vulnerabilities in the guardrails-detectors component. Both issues stem from improper handling of user-supplied XML Schema Definition (XSD) input, enabling Server-Side Request Forgery (SSRF) attacks. A remote attacker could exploit these vulnerabilities to access internal network services, cloud metadata endpoints, or read sensitive local files, potentially exposing credentials, service account tokens, Kubernetes resources, and other confidential information.
CVE-2026-15143 has a CVSS score of 9.3, which is Critical severity. CVE-2026-15378 has a CVSS score of 9.3, which is Critical severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations using affected RHOAI deployments should prioritize applying the available updates to protect sensitive infrastructure and internal resources.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-918