Red Hat Security Advisory: RHOAI 2.25.8 - Red Hat OpenShift AI
Release of RHOAI 2.25.8 provides these changes:
AI Analysis
Technical Summary
The Red Hat OpenShift AI product prior to version 2.25.8 contains multiple security vulnerabilities, including CVE-2026-35029, CVE-2026-35030, and CVE-2026-42271. These vulnerabilities relate to improper resource management and command injection issues as indicated by CWE-425 (Direct Request ('Forced Browsing')), CWE-222 (Truncation Error), and CWE-78 (OS Command Injection). The CVSS vector for CVE-2026-35029 indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. Red Hat has released updated container images and OpenShift AI version 2.25.8 to remediate these vulnerabilities. The vendor advisory explicitly states updated images are available and provides upgrade instructions. No exploits have been observed in the wild to date.
Potential Impact
Successful exploitation of these vulnerabilities could lead to significant compromise of confidentiality, integrity, and availability of the affected OpenShift AI deployments. The CVSS vector indicates high impact on all security properties with low complexity and no user interaction required, increasing the risk if the vulnerabilities are exploited. However, no known exploits have been reported in the wild so far.
Mitigation Recommendations
Red Hat has released updated OpenShift AI images and version 2.25.8 that address these vulnerabilities. Users should upgrade to Red Hat OpenShift AI 2.25.8 following the official upgrade documentation provided by Red Hat to fully apply the errata update. No other mitigations or workarounds are specified. Patch status is confirmed as fixed in version 2.25.8.
Red Hat Security Advisory: RHOAI 2.25.8 - Red Hat OpenShift AI
Description
Release of RHOAI 2.25.8 provides these changes:
CVSS v4.0
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat OpenShift AI product prior to version 2.25.8 contains multiple security vulnerabilities, including CVE-2026-35029, CVE-2026-35030, and CVE-2026-42271. These vulnerabilities relate to improper resource management and command injection issues as indicated by CWE-425 (Direct Request ('Forced Browsing')), CWE-222 (Truncation Error), and CWE-78 (OS Command Injection). The CVSS vector for CVE-2026-35029 indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. Red Hat has released updated container images and OpenShift AI version 2.25.8 to remediate these vulnerabilities. The vendor advisory explicitly states updated images are available and provides upgrade instructions. No exploits have been observed in the wild to date.
Potential Impact
Successful exploitation of these vulnerabilities could lead to significant compromise of confidentiality, integrity, and availability of the affected OpenShift AI deployments. The CVSS vector indicates high impact on all security properties with low complexity and no user interaction required, increasing the risk if the vulnerabilities are exploited. However, no known exploits have been reported in the wild so far.
Mitigation Recommendations
Red Hat has released updated OpenShift AI images and version 2.25.8 that address these vulnerabilities. Users should upgrade to Red Hat OpenShift AI 2.25.8 following the official upgrade documentation provided by Red Hat to fully apply the errata update. No other mitigations or workarounds are specified. Patch status is confirmed as fixed in version 2.25.8.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:28960
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-35030","CVE-2026-42271"]
- Cvss Version
- null
Threat ID: 6a3c0ceaeed863c81e237316
Added to database: 06/24/2026, 16:59:22 UTC
Last enriched: 07/26/2026, 01:17:56 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.