Description
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:53261
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:53262
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:53263
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-15154
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2498188
Updated 16m ago · 8 sources