VDB
CVE-2026-15378
CVE-2026-15378
PUBLISHED
CVSS 9.3 CRITICAL
Reported by redhat · Published July 10, 2026
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Risk Scores
CVSS 3.1
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1786710963 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787360218 |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI 2.25 | 1786710963 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787360218, 1787360218 |
Timeline
- Jul 10, 2026 EPSS Score
- Jul 10, 2026 CVE Published
- Jul 11, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 Distribution Patch
References
- RHSA-2026:60520 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65126 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2498941 issue-trackingx_refsource_REDHAT