Skip to content
Red HatCVE-2026-15378

Red Hat: server-side request forgery

Critical9.3CVE-2026-15378 · Published Jul 10, 2026 · updated Sep 8, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat file_type content: information disclosure
Critical9.3Jul 10
Red Hat libarchive. This vulnerability: denial of service
Low3.9Jul 10
Red Hat GStreamer: buffer overflow
High7.1Jul 9
Red Hat GStreamer: buffer overflow
High7.5Jul 9
Red Hat, Inc.: CVE records (CNA): denial of service
Medium6.5Jul 8
Red Hat gorch service template: missing authentication
Medium6.3Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.