Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13717

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

Отчет

This Important flaw in the Red Hat OpenShift AI (RHOAI) MaaS Gateway stems from an insecure default configuration, allowing a standard user with low privileges to intercept, read, log, and alter all model-serving traffic. This includes sensitive data such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering within any namespace authorized to use the MaaS Gateway.

Меры по смягчению последствий

You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-llmisvc-controller-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-maas-controller-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-model-controller-rhel9Affected
Red Hat OpenShift AI 3.4rhoai/odh-rhel9-operatorFixedRHSA-2026:5326211.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2494203RHOAI MaaS: llm-d: MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)

EPSS

Процентиль: 29%
0.00355
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
8 дней назад

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

CVSS3: 8.8
github
8 дней назад

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

EPSS

Процентиль: 29%
0.00355
Низкий

8.8 High

CVSS3

Уязвимость CVE-2026-13717