Denial of Service Vulnerability in ml-metadata by Red Hat
CVE-2026-18618

7.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-18618?

A vulnerability exists in ml-metadata due to the use of an outdated gRPC stack, rendering it susceptible to HTTP/2 denial of service attacks. An attacker with network access to the MLMD pod within the cluster can exploit this flaw by sending specially crafted HTTP/2 requests. This could result in the failure of the MLMD pod, causing significant disruptions to all active pipeline runs in the affected namespace.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.