← All Advisories

CVE-2026-18618

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-18618

Key Details

CVECVE-2026-18618
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsRed Hat Red Hat OpenShift AI 3.3, Red Hat Red Hat OpenShift AI 3.4, Red Hat Red Hat OpenShift AI 2.25, and Red Hat Red Hat OpenShift AI 3.5
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat OpenShift AI 2.25
Red HatRed Hat OpenShift AI 3.5
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18618
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18618