CVE-2026-18618
7.5Red Hat · OpenShift AI
A resource allocation flaw in the ml-metadata component of Red Hat OpenShift AI 3.3 may allow an unauthenticated attacker to cause a denial-of-service condition.
Executive summary
A high-severity denial-of-service vulnerability in Red Hat OpenShift AI 3.3 could allow remote attackers to exhaust system resources.
Vulnerability
This vulnerability is identified as CWE-770, which involves the allocation of resources without proper limits or throttling. The flaw is remotely exploitable without requiring authentication.
Business impact
An attacker can exploit this vulnerability to trigger a denial-of-service, potentially rendering the ml-metadata service unavailable and disrupting critical machine learning workflows. With a CVSS score of 7.5, this poses a substantial risk to service availability and business continuity for teams relying on OpenShift AI.
Remediation
Immediate Action: Update Red Hat OpenShift AI 3.3 to the version containing the fix, identified as build 1785262015 or later.
Proactive Monitoring: Monitor system resource usage, such as CPU and memory consumption, for sudden spikes or exhaustion patterns indicative of a denial-of-service attempt.
Compensating Controls: Implement rate limiting at the network or API gateway level to prevent excessive requests from reaching the vulnerable component.
Exploitation status
Public Exploit Available: No
Analyst recommendation
To maintain the availability of machine learning services, administrators must apply the security update provided by Red Hat. Implementing strict rate limiting and resource monitoring in the interim will help mitigate the risk of service disruption until the patch can be fully deployed.