Red HatCVE-2026-15378
Red Hat: server-side request forgery
Critical9.3CVE-2026-15378 · Published Jul 10, 2026 · updated Sep 8, 2026
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 10 | Red Hat file_type content: information disclosure | Critical9.3 | Red Hat+1 more |
| Jul 10 | Red Hat libarchive. This vulnerability: denial of service | Low3.9 | No fix yet |
| Jul 9 | Red Hat GStreamer: buffer overflow | High7.1 | No fix yet |
| Jul 9 | Red Hat GStreamer: buffer overflow | High7.5 | No fix yet |
| Jul 8 | Red Hat, Inc.: CVE records (CNA): denial of service | Medium6.5 | Red Hat+1 more |
| Jul 8 | Red Hat gorch service template: missing authentication | Medium6.3 | No fix yet |