Description
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Published: 2026-07-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the guardrails-detectors component allows a remote attacker to submit a crafted XML Schema Definition that triggers blind Server-Side Request Forgery, enabling the attacker to access sensitive information such as cloud metadata services, the Kubernetes API, internal MinIO, and other internal network endpoints, and to read local files on the node, including service-account tokens and pod secrets.

Affected Systems

Red Hat OpenShift AI contains the vulnerable guardrails-detectors component; any deployment that includes this component may be affected, though no specific version range is listed.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, indicating very high severity, while the EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote delivery of a malicious XML schema to the guardrails-detectors endpoint, which causes the component to fetch and process external resources, enabling blind SSRF and local file reads. An attacker with network access to the component can reach internal services or read sensitive files on the node.

Generated by OpenCVE AI on July 29, 2026 at 11:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Red Hat security patch for the guardrails-detectors component or upgrade to a fixed version.
  • Configure the component to reject or strictly validate external XML schemas, or disable schema processing when it is not required.
  • Restrict egress traffic from OpenShift AI clusters to trusted internal services only, and enforce strict network segmentation and access controls.
  • Monitor cluster logs for unexpected internal network requests or local file access attempts and set alerts for anomalous activity.

Generated by OpenCVE AI on July 29, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Openshift Ai (rhoai)
Vendors & Products Red Hat
Red Hat red Hat Openshift Ai (rhoai)

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Title Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
First Time appeared Redhat
Redhat openshift Ai
Weaknesses CWE-918
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Red Hat Red Hat Openshift Ai (rhoai)
Redhat Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-14T01:37:07.099Z

Reserved: 2026-07-10T08:57:01.261Z

Link: CVE-2026-15378

cve-icon Vulnrichment

Updated: 2026-07-14T01:37:02.782Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-10T09:19:44Z

Links: CVE-2026-15378 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)