VDB

CVE-2026-15378

CVE-2026-15378 PUBLISHED CVSS 9.3 CRITICAL

Reported by redhat · Published July 10, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.

Risk Scores

CVSS 3.1
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift AI 2.251786710963
Red HatRed Hat OpenShift AI 3.41787360218
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI 2.251786710963
Red HatRed Hat OpenShift AI 3.41787360218, 1787360218

Timeline

  • Jul 10, 2026 EPSS Score
  • Jul 10, 2026 CVE Published
  • Jul 11, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›