Red HatCVE-2026-18618
Red Hat ml-metadata. The statically-linked gRPC stack: denial of service
High7.5CVE-2026-18618 · Published Aug 10, 2026 · updated Sep 21, 2026
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
- www.cve.org/CVERecord?id=CVE-2026-18618
- nvd.nist.gov/vuln/detail/CVE-2026-18618
- access.redhat.com/errata/RHSA-2026:53261
- access.redhat.com/errata/RHSA-2026:53262
- access.redhat.com/errata/RHSA-2026:53263
- access.redhat.com/errata/RHSA-2026:60367
- access.redhat.com/security/cve/CVE-2026-18618
- bugzilla.redhat.com/show_bug.cgi?id=2510313
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |