Red Hat Linux Security Advisories & CVEs
4700 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-15554] Authentication Bypass via AJP ssl_cert/is_ssl Forgery
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.
High [CVE-2026-72693] Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on `/proc//fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path. A flaw was found in openvt (part of the kbd package) where incorrect process owner verification can allow a local unprivileged attacker to achieve passwordless root login.
High [CVE-2026-72694] MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:57596, RHSA-2026:65832, RHSA-2026:57600. Affected products named by the advisory: Red Hat package: mrtg.
High [CVE-2026-4757] Code execution and privilege escalation via VAPIX API improper input validation
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account. A flaw was found in Axis. An attacker with an administrator-privileged service account could exploit improper input validation in a VAPIX API parameter. This could allow for arbitrary code execution and potentially lead to privilege escalation, granting the attacker higher system privileges. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: axis.
High [CVE-2026-66797] Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin
Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result correctly. This lets any authenticated user write annotations to, and disclose existing annotations/comments on, an entity they don't own by simply supplying its UUID. This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue. A flaw was found in the cluster-backup-operator. An attacker with write access to the backup storage location or the ability to create a Velero Backup object can inject malicious Role-Based Access Control (RBAC) resources into a backup. This allows the attacker to gain administrative control over the entire cluster. This vulnerability is rated as an Important severity for Red Hat Advanced Cluster Management for Kubernetes because exploiting it requires high prerequisites, such as preexisting write access to external object storage or permissions to generate arbitrary backup definitions, despite resulting in full cluster takeover. Weakness: CWE-862.
High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts. This vulnerability is rated as Important because an authenticated user with administrative access to the backup namespace can achieve cluster-wide privilege escalation. By defining custom restore operations containing uninspected execution hooks, an attacker circumvents standard pod execution controls across target restored workloads. This bypass enables unauthorized command execution and credential exfiltration across different namespaces, exceeding the boundary of the backup operator namespace. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-77.
High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a specific namespace could exploit a vulnerability in the backup restoration process. This flaw allows them to redirect sensitive information, such as cloud provider credentials and access tokens, from backup operations into other namespaces, including those they control. This could lead to unauthorized access to critical system resources and the disclosure of confidential data. This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. This allows for a cross-namespace write of credential material, potentially leading to unauthorized access to cloud provider credentials, pull secrets, and ManagedServiceAccount tokens. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N). Weakness: CWE-863. Red Hat fixing advisory: RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:57191, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; and 1 more.
High [CVE-2026-66800] CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources. This vulnerability is rated as Important. A namespace administrator within the `open-cluster-management-backup` namespace in Red Hat Advanced Cluster Management for Kubernetes can initiate a cluster-wide denial of service. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-862. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more.
High [CVE-2026-62901] .NET:.NET Denial of Service Vulnerability
Unchecked input for loop condition in.NET allows an unauthorized attacker to deny service over a network. This vulnerability in System. Net.WebSockets is rated as Important. An unauthenticated attacker could exploit this flaw to cause a denial of service in affected.NET applications, impacting service availability and reliability. This affects Red Hat products utilizing.NET 6.0 and newer versions. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:54541, RHSA-2026:54590, RHSA-2026:55858, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:54538, RHSA-2026:54542, RHSA-2026:54550, RHSA-2026:54574, RHSA-2026:55856, RHSA-2026:55857, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:44914, RHSA-2026:55142, RHSA-2026:55405. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.
High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability
Uncaught exception in.NET allows an authorized attacker to elevate privileges locally. This vulnerability is rated as Important. A truncation error in the.NET diagnostics IPC, specifically within ipc_transport_get_default_name when processing excessively long TMPDIR paths, could lead to a local elevation of privilege. This allows an attacker with local access to potentially gain higher privileges on the system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-252. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:54541, RHSA-2026:54590, RHSA-2026:55858, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:54538, RHSA-2026:54542, RHSA-2026:54550, RHSA-2026:54574, RHSA-2026:55856, RHSA-2026:55857, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:44914, RHSA-2026:55142, RHSA-2026:55405. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.
High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters. This Important flaw in Multicluster Engine for Kubernetes' clusterclaims-controller allows a tenant to propagate arbitrary labels from a ClusterClaim to a ManagedCluster object. This enables unauthorized cross-tenant ManagedClusterSet joins, leading to policy and workload injection into victim clusters. The vulnerability breaks tenant isolation, granting an attacker control over resources belonging to other tenants. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-441. Affected Red Hat products: multicluster engine for Kubernetes 2.1; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9. Red Hat fixing advisory: RHSA-2026:59557, RHSA-2026:59556, RHSA-2026:59593, RHSA-2026:59579, RHSA-2026:59558, RHSA-2026:59559.
High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or other tenants' clusters, due to a missing ownership check. This vulnerability can lead to a denial of service by enabling unauthorized deletion of ManagedClusters. This is an Important flaw in Multicluster Engine for Kubernetes. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). Weakness: CWE-602. Affected Red Hat products: multicluster engine for Kubernetes 2.1; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9. Red Hat fixing advisory: RHSA-2026:59557, RHSA-2026:59556, RHSA-2026:59593, RHSA-2026:59579, RHSA-2026:59558, RHSA-2026:59559.
High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. A flaw was found in console. When the `HTTPS_PROXY` environment variable is not configured, the console component fails to verify Transport Layer Security (TLS) certificates for outbound connections. A network-positioned attacker (Man-in-the-Middle) can exploit this vulnerability to intercept the cluster pull-secret while it is being sent to console.redhat.com. This pull-secret is a critical credential that provides access to Red Hat container registries and cloud services, potentially leading to unauthorized access and sensitive information disclosure. This allows a network-positioned attacker to intercept the cluster pull-secret, a high-value credential, due to the lack of server certificate validation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: multicluster engine for Kubernetes 2.6; Red Hat Advanced Cluster Management for Kubernetes 2.11. Red Hat fixing advisory: RHSA-2026:59579, RHSA-2026:60387.
High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2. This could lead to a complete compromise of the user's system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: External Secrets Operator for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat lists Logging Subsystem for Red Hat OpenShift as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.
High [CVE-2026-63622] swtpm privilege escalation via symlink following
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough. This is a Critical vulnerability. This allows any namespace editor to escalate privileges by creating training jobs that can impersonate ServiceAccounts, mount hostPath volumes, set privileged security contexts, and achieve remote code execution, expanding the attack surface beyond users explicitly granted training workload access. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4; Red Hat OpenShift AI 3.5. Red Hat fixing advisory: RHSA-2026:53261, RHSA-2026:53263, RHSA-2026:53262, RHSA-2026:60520, RHSA-2026:60367.
High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution. This issue is specific to the RHOAI fork and not present in upstream Kubeflow trainer. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-267. Affected Red Hat products: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4; Red Hat OpenShift AI 3.5. Red Hat fixing advisory: RHSA-2026:53263, RHSA-2026:73987, RHSA-2026:53262, RHSA-2026:60520, RHSA-2026:60367.
High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system. By crafting a RoleBinding with an arbitrary roleRef, an attacker can grant themselves any ClusterRole, including 'cluster-admin', within their namespace. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Red Hat fixing advisory: RHSA-2026:53261, RHSA-2026:53263, RHSA-2026:53262.
High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation. A compromised dashboard Service Account could read and delete sensitive secrets across the cluster and create `ClusterRoleBindings`, leading to full cluster-admin privilege escalation and breaking multi-tenant isolation. This risk is present in Red Hat OpenShift AI deployments with the dashboard component enabled. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI). Red Hat fixing advisory: RHSA-2026:53261, RHSA-2026:53263, RHSA-2026:53262.
High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization
Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.