Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Thu, 26 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data. |
| Title | llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy | Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy |
| First Time appeared |
Redhat
Redhat openshift Ai |
|
| CPEs | cpe:/a:redhat:openshift_ai cpe:/a:redhat:openshift_ai:2.25::el9 |
|
| Vendors & Products |
Redhat
Redhat openshift Ai |
|
| References |
|
Wed, 04 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-03-26T21:48:16.762Z
Reserved: 2025-11-06T13:48:05.305Z
Link: CVE-2025-12805
No data.
Status : Received
Published: 2026-03-26T22:16:25.920
Modified: 2026-03-26T22:16:25.920
Link: CVE-2025-12805
OpenCVE Enrichment
No data.