Red Hat Security Advisory: RHOAI 2.17.0 - Red Hat OpenShift AI
Release of RHOAI 2.17.0 provides these changes:
AI Analysis
Technical Summary
Red Hat OpenShift Container Platform 4.17.15 and associated products have multiple security vulnerabilities affecting various components and libraries. These include CVE-2024-21538 (Regular expression denial of service in cross-spawn), CVE-2024-45590 (Denial of Service in body-parser), CVE-2024-48910 (Prototype pollution in DOMPurify), CVE-2024-56201 (Sandbox breakout in Jinja2), CVE-2024-43796 (Improper input handling in Express redirects), CVE-2024-43799 (Code execution in Send library), CVE-2024-43800 (Improper sanitization in serve-static), and others. Red Hat has issued security advisories RHSA-2024:10186 and RHSA-2025:3368 detailing fixes and updated images. The advisories recommend upgrading to patched versions such as RHACS 4.5.5 and RHOAI 2.16.0. The vulnerabilities span multiple CWEs including input validation errors, memory corruption, and denial of service conditions. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities collectively could allow attackers to cause denial of service, execute arbitrary code, bypass sandbox restrictions, or tamper with application behavior through prototype pollution or improper input handling. These impacts could affect the confidentiality, integrity, and availability of affected Red Hat OpenShift deployments and associated Kubernetes security components. However, there are no reports of active exploitation in the wild. The severity is assessed as high due to the potential for code execution and denial of service.
Mitigation Recommendations
Red Hat has released official patches and updated container images to address these vulnerabilities. Users should upgrade to Red Hat OpenShift Container Platform 4.17.15, Red Hat Advanced Cluster Security for Kubernetes 4.5.5, and Red Hat OpenShift AI 2.16.0 or later as applicable. The vendor manages remediation for these products through official updates and advisories. Applying these updates will mitigate the vulnerabilities. No additional vendor-recommended mitigations or workarounds are indicated in the advisory.
Red Hat Security Advisory: RHOAI 2.17.0 - Red Hat OpenShift AI
Description
Release of RHOAI 2.17.0 provides these changes:
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat OpenShift Container Platform 4.17.15 and associated products have multiple security vulnerabilities affecting various components and libraries. These include CVE-2024-21538 (Regular expression denial of service in cross-spawn), CVE-2024-45590 (Denial of Service in body-parser), CVE-2024-48910 (Prototype pollution in DOMPurify), CVE-2024-56201 (Sandbox breakout in Jinja2), CVE-2024-43796 (Improper input handling in Express redirects), CVE-2024-43799 (Code execution in Send library), CVE-2024-43800 (Improper sanitization in serve-static), and others. Red Hat has issued security advisories RHSA-2024:10186 and RHSA-2025:3368 detailing fixes and updated images. The advisories recommend upgrading to patched versions such as RHACS 4.5.5 and RHOAI 2.16.0. The vulnerabilities span multiple CWEs including input validation errors, memory corruption, and denial of service conditions. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities collectively could allow attackers to cause denial of service, execute arbitrary code, bypass sandbox restrictions, or tamper with application behavior through prototype pollution or improper input handling. These impacts could affect the confidentiality, integrity, and availability of affected Red Hat OpenShift deployments and associated Kubernetes security components. However, there are no reports of active exploitation in the wild. The severity is assessed as high due to the potential for code execution and denial of service.
Mitigation Recommendations
Red Hat has released official patches and updated container images to address these vulnerabilities. Users should upgrade to Red Hat OpenShift Container Platform 4.17.15, Red Hat Advanced Cluster Security for Kubernetes 4.5.5, and Red Hat OpenShift AI 2.16.0 or later as applicable. The vendor manages remediation for these products through official updates and advisories. Applying these updates will mitigate the vulnerabilities. No additional vendor-recommended mitigations or workarounds are indicated in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:0875
- Cve Count
- 12
- Additional Cves
- ["CVE-2024-43796","CVE-2024-43799","CVE-2024-43800","CVE-2024-45296","CVE-2024-45338","CVE-2024-45590","CVE-2024-48910","CVE-2024-52798","CVE-2024-55565","CVE-2024-56201","CVE-2024-56326"]
Threat ID: 6a18be67e29bf47b50388269
Added to database: 05/28/2026, 22:15:03 UTC
Last enriched: 08/14/2026, 23:26:40 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 111
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.