Skip to content
Red HatCVE-2026-15154

Red Hat, Inc.: CVE records (CNA): denial of service

Medium6.5CVE-2026-15154 · Published Jul 8, 2026 · updated Sep 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat, Inc.: CVE records (CNA)
Product
< d857e059f8a2dedb5c7ea9a2c307c4cfd7983fd1d857e059f8a2dedb5c7ea9a2c307c4cfd7983fd1
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat gorch service template: missing authentication
Medium6.3Jul 8
Red Hat TrustyAI Service Operator.: information disclosure
Medium6.3Jul 8
A flaw was found in 389 Directory Server
Low3.7Jul 8
Red Hat Jastow: cross-site scripting
Medium6.5Jul 7
Red Hat GStreamer: incorrect control flow
Low3.7Jul 7
Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted
Medium4.4Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.