Skip to content
Red HatCVE-2026-15143

Red Hat file_type content: information disclosure

Critical9.3CVE-2026-15143 · Published Jul 10, 2026 · updated Aug 31, 2026

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift AI (RHOAI)
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat, Inc.: CVE records (CNA)
Product
< 985c6d5a4a84360ff8b447b94e4a3cdfbda3da90985c6d5a4a84360ff8b447b94e4a3cdfbda3da90
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Red Hat advisories

All Red Hat
Advisory
Red Hat libarchive. This vulnerability: denial of service
Low3.9Jul 10
Red Hat: server-side request forgery
Critical9.3Jul 10
Red Hat GStreamer: buffer overflow
High7.1Jul 9
Red Hat GStreamer: buffer overflow
High7.5Jul 9
Red Hat, Inc.: CVE records (CNA): denial of service
Medium6.5Jul 8
Red Hat gorch service template: missing authentication
Medium6.3Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.