CVE 8.1 HIGH

Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy_CVE-2025-12805

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data.

Basic Information

ID CVE-2025-12805
Source redhat
Published Mar 26, 2026 at 21:48
Modified Mar 31, 2026 at 03:55

Affected Product

Vendor Red Hat
Product Red Hat OpenShift AI 2.25
Version sha256:c0d95dfbae20e87113ffb81026d379bb63ad300447df98b27d1bf9a83b084744

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.