Denial of Service Vulnerability in ml-metadata by Red Hat
CVE-2026-18618
7.5HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-18618?
A vulnerability exists in ml-metadata due to the use of an outdated gRPC stack, rendering it susceptible to HTTP/2 denial of service attacks. An attacker with network access to the MLMD pod within the cluster can exploit this flaw by sending specially crafted HTTP/2 requests. This could result in the failure of the MLMD pod, causing significant disruptions to all active pipeline runs in the affected namespace.
Affected Version(s)
Red Hat OpenShift AI 2.25 1785260280
Red Hat OpenShift AI 3.3 1785262015
Red Hat OpenShift AI 3.4 1785269945