Denial of Service Vulnerability in ml-metadata by Red Hat
CVE-2026-18618

7.5HIGH

What is CVE-2026-18618?

A vulnerability exists in ml-metadata due to the use of an outdated gRPC stack, rendering it susceptible to HTTP/2 denial of service attacks. An attacker with network access to the MLMD pod within the cluster can exploit this flaw by sending specially crafted HTTP/2 requests. This could result in the failure of the MLMD pod, causing significant disruptions to all active pipeline runs in the affected namespace.

Affected Version(s)

Red Hat OpenShift AI 2.25 1785260280

Red Hat OpenShift AI 3.3 1785262015

Red Hat OpenShift AI 3.4 1785269945

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.