CVE-2026-18948: Red Hat Openshift Ai 2.25

Critical severity, CVSS 9.9. EPSS: 1.1% chance of exploitation in the next 30 days.

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.

Affected products

  • Red Hat Red Hat Openshift Ai 2.25: before 1786110051 (fixed in 1786110051)
  • Red Hat Red Hat Openshift Ai 3.3: before 1786110033 (fixed in 1786110033)
  • Red Hat Red Hat Openshift Ai 3.4: before 1786107278 (fixed in 1786107278); before 1787068065 (fixed in 1787068065)
  • Red Hat Red Hat Openshift Ai Rhoai

Published 2026-08-10. Last modified 2026-09-28.