Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-15378
Red Hat Red Hat OpenShift AI 2.25 — Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C H L N 9.3 .0053 42.6 —
AFFECTED
Product Versions Fixed
Red Hat OpenShift AI 2.25 unspecified 1786710963
Red Hat OpenShift AI 3.3 unspecified 1789656673
Red Hat OpenShift AI 3.4 unspecified 1787360218
TIMELINE
Jul 10 Reserved by redhat
Jul 10 Published (CNA: redhat)
Aug 26 PATCH SHIPPED — CVE-2026-15378 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787360218.
Description
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 10, 2026 | Reserved | Reserved by redhat |
| July 10, 2026 | Published | Published (CNA: redhat) |
| August 26, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-15378 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787360218. |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat OpenShift AI 2.25 | — | — | 1786710963 |
| Red Hat | Red Hat OpenShift AI 3.3 | — | — | 1789656673 |
| Red Hat | Red Hat OpenShift AI 3.4 | — | — | 1787360218 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-15378 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.