CVE-2026-18618: Red Hat Openshift Ai 2.25
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.
Affected products
- Red Hat Red Hat Openshift Ai 2.25: before 1785260280 (fixed in 1785260280)
- Red Hat Red Hat Openshift Ai 3.3: before 1785262015 (fixed in 1785262015)
- Red Hat Red Hat Openshift Ai 3.4: before 1785269945 (fixed in 1785269945)
- Red Hat Red Hat Openshift Ai 3.5: before 1786552271 (fixed in 1786552271); before 1786552250 (fixed in 1786552250)
Published 2026-08-10. Last modified 2026-09-21.