CVE-2026-15154

⚪ Do wiadomości

Błąd w guardrails-detectors w Red Hat OpenShift AI pozwala na atak typu DoS przez złośliwe wyrażenia regularne.

CVSS
6.5
EPSS
0.5%
Exploit
none
Vendor
redhat
Opis źródłowy (NVD)

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-07-08 20:16:48 UTC
Ostatnia modyfikacja (NVD)2026-08-27 17:17:11 UTC
Referencje