Redhat Enterprise Linux Ai vulnerabilities
3 known vulnerabilities affecting redhat/enterprise_linux_ai.
Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-48710P1MEDIUMCVSS 6.5KEVPoCRansomwarev3.02026-05-26
CVE-2026-48710 [MEDIUM] CWE-444 CVE-2026-48710: Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request h
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the p
nvd
CVE-2026-6859P3HIGHCVSS 8.8v3.02026-04-22
CVE-2026-6859 [HIGH] CWE-829 CVE-2026-6859: A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` with a specially crafted malicious model from the HuggingFace Hub. This vulnerability can
nvd
CVE-2026-6855P3HIGHCVSS 7.1v3.02026-04-22
CVE-2026-6855 [HIGH] CWE-22 CVE-2026-6855: A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in th
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
nvd