Red HatCVE-2026-15143
Red Hat file_type content: information disclosure
Critical9.3CVE-2026-15143 · Published Jul 10, 2026 · updated Aug 31, 2026
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift AI (RHOAI) Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat, Inc.: CVE records (CNA) Product | < 985c6d5a4a84360ff8b447b94e4a3cdfbda3da90 | 985c6d5a4a84360ff8b447b94e4a3cdfbda3da90 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 10 | Red Hat libarchive. This vulnerability: denial of service | Low3.9 | No fix yet |
| Jul 10 | Red Hat: server-side request forgery | Critical9.3 | No fix yet |
| Jul 9 | Red Hat GStreamer: buffer overflow | High7.1 | No fix yet |
| Jul 9 | Red Hat GStreamer: buffer overflow | High7.5 | No fix yet |
| Jul 8 | Red Hat, Inc.: CVE records (CNA): denial of service | Medium6.5 | Red Hat+1 more |
| Jul 8 | Red Hat gorch service template: missing authentication | Medium6.3 | No fix yet |