Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 94%

Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI

0
Critical
Published: 03/04/2026 (03/04/2026, 07:18:30 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 3.3 provides these changes:

Affected software

Affected versions
Red HatRed Hat OpenShift AIRed Hat OpenShift AI 3.3amd64registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:894f3f6f3b8de4c4a448284d12ac7a8bddecc370d64aa71e02ace54d68778e35_amd64Red Hat Advanced Cluster Management for KubernetesRed Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:bbe086814cc2fe9e53699ff23705479b493a62f9521b5f2664fcdb97dd5705a9_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.22registry.redhat.io/odf4/cephcsi-rhel9@sha256:05df2bcbadb214e4873082f282ef013565f04f24dce406d3802288d6ad574741_amd64OpenShift API for Data ProtectionOpenShift API for Data Protection 1.5registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:2c9332fa68acce79d7defcec12c651d6d331a32208f4325e798cf37971a35fed_amd64

Weaknesses

CWE-279CWE-918CWE-22CWE-179CWE-476CWE-502CWE-94CWE-770CWE-130CWE-59CWE-208CWE-1050CWE-787CWE-78CWE-674CWE-91CWE-1188CWE-409CWE-405CWE-73CWE-400CWE-1333CWE-119CWE-209CWE-1286CWE-367CWE-1241CWE-1284CWE-551CWE-131CWE-303CWE-190CWE-276CWE-88CWE-20CWE-909CWE-771CWE-79CWE-354CWE-606CWE-524CWE-1289CWE-772CWE-281CWE-347CWE-358CWE-426CWE-601CWE-427CWE-295CWE-681CWE-1287CWE-436

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:59:19 UTC

Technical Analysis

This advisory covers a critical security update for Red Hat OpenShift AI 3.3, which addresses a total of 46 CVEs including CVE-2024-25621. The vulnerabilities span a wide range of CWEs such as improper access control, path traversal, use-after-free, code injection, and others. The advisory announces the release of updated container images for Red Hat OpenShift AI 3.3 but does not provide detailed technical descriptions or explicit patch information within the provided data. The vendor directs users to official documentation for upgrade procedures.

Potential Impact

The vulnerabilities are classified as critical and affect Red Hat OpenShift AI 3.3. The broad range of CWEs suggests potential for serious security issues including unauthorized access, code execution, and denial of service. However, no known exploits in the wild have been reported at this time. The impact is significant due to the critical severity and the number of CVEs addressed.

Mitigation Recommendations

Updated images for Red Hat OpenShift AI 3.3 are available as part of this advisory. Users should follow the official Red Hat documentation to upgrade their clusters and fully apply this errata update. Patch status is confirmed by the availability of updated images and the vendor's advisory. No additional mitigation steps are specified beyond applying the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3713
Cve Count
46
Additional Cves
["CVE-2025-6242","CVE-2025-12638","CVE-2025-12816","CVE-2025-14180","CVE-2025-14920","CVE-2025-14921","CVE-2025-14922","CVE-2025-14924","CVE-2025-14925","CVE-2025-14926","CVE-2025-14927","CVE-2025-14928","CVE-2025-14929","CVE-2025-14930","CVE-2025-15284","CVE-2025-48956","CVE-2025-52881","CVE-2025-59425","CVE-2025-61726","CVE-2025-61729","CVE-2025-62164","CVE-2025-62593","CVE-2025-64756","CVE-2025-66031","CVE-2025-66034","CVE-2025-66416","CVE-2025-66418","CVE-2025-66448","CVE-2025-66471","CVE-2025-66506","CVE-2025-66626","CVE-2025-67725","CVE-2025-67726","CVE-2025-68156","CVE-2025-68476","CVE-2025-68665","CVE-2025-69223","CVE-2025-69872","CVE-2026-0897","CVE-2026-1260","CVE-2026-21441","CVE-2026-22778","CVE-2026-22807","CVE-2026-24049","CVE-2026-24486"]
Cvss Version
null

Threat ID: 6a160964e29bf47b506297b7

Added to database: 05/26/2026, 20:58:12 UTC

Last enriched: 07/25/2026, 23:59:19 UTC

Last updated: 07/31/2026, 19:30:12 UTC

Views: 251

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:3713https://access.redhat.com/security/cve/CVE-2024-25621https://access.redhat.com/security/cve/CVE-2025-12638https://access.redhat.com/security/cve/CVE-2025-12816https://access.redhat.com/security/cve/CVE-2025-14180https://access.redhat.com/security/cve/CVE-2025-14920https://access.redhat.com/security/cve/CVE-2025-14921https://access.redhat.com/security/cve/CVE-2025-14922https://access.redhat.com/security/cve/CVE-2025-14924https://access.redhat.com/security/cve/CVE-2025-14925https://access.redhat.com/security/cve/CVE-2025-14926https://access.redhat.com/security/cve/CVE-2025-14927https://access.redhat.com/security/cve/CVE-2025-14928https://access.redhat.com/security/cve/CVE-2025-14929https://access.redhat.com/security/cve/CVE-2025-14930https://access.redhat.com/security/cve/CVE-2025-15284https://access.redhat.com/security/cve/CVE-2025-48956https://access.redhat.com/security/cve/CVE-2025-52881https://access.redhat.com/security/cve/CVE-2025-59425https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/errata/RHSA-2026:25127https://access.redhat.com/security/cve/CVE-2025-61728https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2025-68151https://access.redhat.com/security/cve/CVE-2026-21441https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-26017https://access.redhat.com/security/cve/CVE-2026-26018https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32936https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-35579https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37387https://access.redhat.com/security/cve/CVE-2024-40635https://access.redhat.com/security/cve/CVE-2024-45310https://access.redhat.com/security/cve/CVE-2025-21613https://access.redhat.com/security/cve/CVE-2025-21614https://access.redhat.com/security/cve/CVE-2025-22870https://access.redhat.com/security/cve/CVE-2025-47911https://access.redhat.com/security/cve/CVE-2025-54410https://access.redhat.com/security/cve/CVE-2025-58058https://access.redhat.com/security/cve/CVE-2025-64329https://access.redhat.com/security/cve/CVE-2025-66506https://access.redhat.com/security/cve/CVE-2025-8766https://access.redhat.com/security/cve/CVE-2026-22772https://access.redhat.com/security/cve/CVE-2026-23831https://access.redhat.com/security/cve/CVE-2026-24117https://access.redhat.com/security/cve/CVE-2026-25680https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-25934https://access.redhat.com/errata/RHSA-2026:2343https://access.redhat.com/security/cve/CVE-2025-58183https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restoreCanonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses