Description
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.
Published: 2026-08-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was found in ml-metadata. The statically linked gRPC stack is outdated, vulnerable to known HTTP/2 denial‑of‑service vulnerabilities. An in‑cluster attacker with network access to the MLMD pod could exploit this by sending specially crafted HTTP/2 requests, causing the pod to crash and all pipeline runs in that namespace to fail. The weakness is a resource exhaustion flaw (CWE‑770) that permits denial of service.

Affected Systems

This issue affects Red Hat OpenShift AI (RHOAI). The vulnerable component is the ml‑metadata service running within the MLMD pod, which listens on port 8080. No specific version range is provided, so all RHOAI installations that include ml‑metadata are potentially impacted until a patch or updated gRPC stack is deployed.

Risk and Exploitability

The CVSS score is 7.5, indicating moderate to high severity, and the vulnerability is currently not listed in the CISA KEV catalog and has no EPSS score available. An attacker consistent with the in‑cluster profile would need connectivity to the pod’s 8080 port, so enforcing network policies to limit which pods may contact the MLMD service mitigates the risk. If the restrictions are bypassed, the denial of service can propagate to every pipeline in the affected namespace, effectively halting business processes.

Generated by OpenCVE AI on August 10, 2026 at 22:38 UTC.

Remediation

Vendor Workaround

To mitigate this issue, ensure that network policies are strictly enforced to limit access to the MLMD pod's port 8080. Restrict inbound connections to only essential KFP v2 driver pods and other designated DSP components. This measure reduces the attack surface by limiting potential in-cluster attackers who could exploit the gRPC HTTP/2 denial-of-service vulnerabilities.


OpenCVE Recommended Actions

  • Apply the vendor patch for Red Hat OpenShift AI when it becomes available.
  • Enforce network policies to restrict inbound traffic to the MLMD pod’s port 8080 so that only KFP v2 driver pods and designated DSP components can reach it.
  • Monitor pod logs and network traffic for abnormal HTTP/2 activity and consider restarting or rescheduling the MLMD pod to mitigate impact.

Generated by OpenCVE AI on August 10, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:2.25::el9
cpe:/a:redhat:openshift_ai:3.4::el9
References

Tue, 11 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai cpe:/a:redhat:openshift_ai:3.3::el9
References

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 10 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.
Title Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachable on listener
First Time appeared Redhat
Redhat openshift Ai
Weaknesses CWE-770
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T18:48:24.225Z

Reserved: 2026-08-03T07:43:02.469Z

Link: CVE-2026-18618

cve-icon Vulnrichment

Updated: 2026-08-11T15:55:01.852Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T21:17:20.370

Modified: 2026-08-14T19:07:46.080

Link: CVE-2026-18618

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-10T18:49:28Z

Links: CVE-2026-18618 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T02:45:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling