Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-12805— Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy

CVSS 8.1 · High EPSS 0.01% · P3
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-12805

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
不充分的划分
Source: NVD (National Vulnerability Database)
Vulnerability Title
Llama Stack 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Llama Stack是Meta Llama开源的一个简化人工智能应用开发的核心构建模块。 Llama Stack存在安全漏洞,该漏洞源于缺少网络策略限制对llama-stack服务端点的访问,可能导致未经授权访问部署在其他命名空间中的Llama Stack服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat OpenShift AI 2.25 sha256:c0d95dfbae20e87113ffb81026d379bb63ad300447df98b27d1bf9a83b084744 ~ * cpe:/a:redhat:openshift_ai:2.25::el9
Red HatRed Hat OpenShift AI 2.25 sha256:1d258fe98c2477e4256a9b936f412f2501fb7ca9e3b810347f9712e0d5ce5c92 ~ * cpe:/a:redhat:openshift_ai:2.25::el9
Red HatRed Hat OpenShift AI (RHOAI)-cpe:/a:redhat:openshift_ai
Red HatRed Hat OpenShift AI (RHOAI)-cpe:/a:redhat:openshift_ai

II. Public POCs for CVE-2025-12805

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-12805

登录查看更多情报信息。

Same Patch Batch · Red Hat · 2026-03-26 · 17 CVEs total

CVE-2026-19618.0 HIGHForman: foreman: remote code execution via command injection in websocket proxy
CVE-2026-24366.5 MEDIUMLibsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-31216.5 MEDIUMKeycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-client
CVE-2026-48876.1 MEDIUMGimp: gimp:memory disclosure and denial of service via specially crafted pcx image
CVE-2026-48975.5 MEDIUMPolkit: polkit: denial of service via unbounded input processing through standard input
CVE-2026-21005.3 MEDIUMP11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-22724.3 MEDIUMGimp: gimp: memory corruption due to integer overflow in ico file handling
CVE-2026-31904.3 MEDIUMKeycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protec
CVE-2026-22713.3 LOWGimp: gimp: denial of service via crafted psp image file
CVE-2026-09683.1 LOWLibssh: libssh: denial of service due to malformed sftp message
CVE-2026-48743.1 LOWOrg.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side r
CVE-2026-22392.8 LOWGimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow
CVE-2026-0965Libssh: libssh: denial of service via improper configuration file handling
CVE-2026-0967Libssh: libssh: denial of service via inefficient regular expression processing
CVE-2026-0964Libssh: improper sanitation of paths received from scp servers
CVE-2026-0966Libssh: buffer underflow in ssh_get_hexa() on invalid input

IV. Related Vulnerabilities

V. Comments for CVE-2025-12805

No comments yet


Leave a comment