Regular Expression Vulnerability in Red Hat OpenShift AI's Guardrails-Detectors
CVE-2026-15154

6.5MEDIUM

What is CVE-2026-15154?

A vulnerability exists in the guardrails-detectors component of Red Hat OpenShift AI that exposes systems to a Denial of Service (DoS) attack via Regular Expression Denial of Service (ReDoS). By sending specially crafted regular expressions to the public detection API, a remote attacker can trigger catastrophic backtracking in the regex engine. This condition can lead to excessive CPU usage, effectively causing the guardrails-mediated LLM pipeline to become unresponsive. As a result, resource consumption may spike to 100%, disrupting service availability for users reliant on the API.

Affected Version(s)

Red Hat OpenShift AI 2.25 1784230964

Red Hat OpenShift AI 3.3 1785137880

Red Hat OpenShift AI 3.4 1783569145

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.