{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-15154","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-07-08T19:44:43.020Z","datePublished":"2026-07-08T19:50:51.563Z","dateUpdated":"2026-09-30T16:55:29.743Z"},"containers":{"cna":{"title":"Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex","metrics":[{"other":{"content":{"value":"Moderate","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline."}],"affected":[{"versions":[{"status":"affected","version":"0","lessThan":"d857e059f8a2dedb5c7ea9a2c307c4cfd7983fd1","versionType":"git"}],"packageName":"guardrails-detectors","collectionURL":"https://github.com/trustyai-explainability/guardrails-detectors","defaultStatus":"unaffected"},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1784230964","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:2.25::el9"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1787235925","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:2.25::el9"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.3","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1785137880","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:3.3::el9"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.3","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1789573032","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:3.3::el9"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1783569145","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:3.4::el9"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-built-in-detector-rhel9","defaultStatus":"affected","versions":[{"version":"1786617316","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_ai:3.4::el9"]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:53261","name":"RHSA-2026:53261","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:53262","name":"RHSA-2026:53262","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:53263","name":"RHSA-2026:53263","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:60520","name":"RHSA-2026:60520","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:65126","name":"RHSA-2026:65126","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:73987","name":"RHSA-2026:73987","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-15154","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498188","name":"RHBZ#2498188","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-07-08T18:43:36.000Z","problemTypes":[{"descriptions":[{"cweId":"CWE-1333","description":"Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-1333: Inefficient Regular Expression Complexity","timeline":[{"lang":"en","time":"2026-06-26T12:47:20.317Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-07-08T18:43:36.000Z","value":"Made public."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-09-30T16:55:29.743Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-08T20:38:40.332330Z","id":"CVE-2026-15154","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-08T20:38:46.315Z"}}]}}