CVE-2026-12151
Red Hat Security Advisory: RHOAI 3.4.4 - Red Hat OpenShift AI
Description
A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.
Metrics
Weakness classes (CWE)
CWE-400Class
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
cwe.mitre.org →CWE-770Base
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/12xxx/CVE-2026-12151.json">CVE-2026-12151</a>
- CVE Modified2026-09-09 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/12xxx/CVE-2026-12151.json">CVE-2026-12151</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:65126
- CVE Modified2026-08-31 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/12xxx/CVE-2026-12151.json">CVE-2026-12151</a>
- CVE Modified2026-08-28 16:17 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
- Reference: https://cna.openjsf.org/security-advisories.html
- Reference: https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q
- Reference: https://cna.openjsf.org/security-advisories.html
- Reference: https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q
- CVE Modified2026-08-28 16:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/12xxx/CVE-2026-12151.json">CVE-2026-12151</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:34342
- Reference: https://access.redhat.com/errata/RHSA-2026:35841
- Reference: https://access.redhat.com/errata/RHSA-2026:35842
Affected operating systems
linux
debian / aomtrixie
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux_ai3.0
linux
ubuntu / ffmpegbionic
linux
ubuntu / ffmpegfocal
linux
ubuntu / ffmpegjammy
linux
ubuntu / ffmpegnoble
linux
ubuntu / ffmpegxenial
linux
ubuntu / pyasn1jammy
linux
ubuntu / pyasn1noble
linux
ubuntu / pyasn1resolute
linux
debian / starlettetrixie
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
aiohttp
aiohttp3.14.0
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
axios
axios0.19.0 – 0.31.1
axios
axios1.0.0 – 1.15.2
axios
axios1.0.0 – 1.16.0
axios
axios1.7.0 – 1.16.0
axios
axios0.32.0
beaugunderson
ip-address10.1.1
bitnami
argo-workflows3.0.0
bitnami
jupyterlab4.0.0
bitnami
jupyterlab
bitnami
mlflow
bitnami
pillow10.3.0
bitnami
pillow5.1.0
References & sources
- https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6web
- https://nvd.nist.gov/vuln/detail/CVE-2026-13676advisory
- https://github.com/fastify/fast-uri/pull/188web
- https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05web
- https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bdweb
- https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1dweb
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.jsonweb
- https://github.com/fastify/fast-uri/releases/tag/v4.0.1web
- https://github.com/fastify/fast-uri/releases/tag/v3.1.3web
- https://github.com/fastify/fast-uri/releases/tag/v2.4.2web
- https://github.com/fastify/fast-uripackage
- https://cna.openjsf.org/security-advisories.htmlweb
- https://bugzilla.redhat.com/show_bug.cgi?id=2494197web
- https://access.redhat.com/security/cve/CVE-2026-13676web
- https://access.redhat.com/errata/RHSA-2026:48126web
- https://access.redhat.com/errata/RHSA-2026:48124web
- https://access.redhat.com/errata/RHSA-2026:44268web
- https://access.redhat.com/errata/RHSA-2026:44239web
- https://access.redhat.com/errata/RHSA-2026:43038web
- https://access.redhat.com/errata/RHSA-2026:42815web
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-8643
A flaw was found in pip, the package installer for Python.
highCVSSv3 8.0 - CVE-2026-69244
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework.
high - CVE-2026-69243
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework.
medium - CVE-2026-69192
A flaw was found in the `ip-address` library.
high - CVE-2026-69152
A flaw was found in the brace-expansion library.
highCVSSv3 7.5 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-64849Actively exploited
A flaw was found in MLflow.
criticalCVSSv3 9.3 - CVE-2026-64835
A flaw was found in FFmpeg.
highCVSSv3 8.8 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-59886
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value.
highCVSSv3 7.5 - CVE-2026-59885
A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1).
highCVSSv3 7.5 - CVE-2026-59884
A flaw was found in pyasn1, a generic ASN.1 library for Python.
highCVSSv3 7.5 - CVE-2026-59874
A flaw was found in node-tar, a tar archive manipulation library for Node.js.
highCVSSv3 7.5 - CVE-2026-59873
A flaw was found in node-tar, a tar archive manipulation library for Node.js.
criticalCVSSv3 7.5 - CVE-2026-59869
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-59205
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-59204
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-59200
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-59199
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-59197
A flaw was found in Pillow prior to 12.3.0.
highCVSSv3 8.2 - CVE-2026-58049
A flaw was found in FFmpeg's RASC video decoder.
highCVSSv3 8.6 - CVE-2026-56211
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation.
highCVSSv3 7.1 - CVE-2026-56210
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation.
highCVSSv3 7.1
Show 118 more CVEs
- CVE-2026-56209
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation.
highCVSSv3 7.1 - CVE-2026-56208
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation.
highCVSSv3 7.6 - CVE-2026-56121
A flaw was found in Feast.
criticalCVSSv3 9.8 - CVE-2026-55685
A flaw was found in React Router.
highCVSSv3 7.5 - CVE-2026-55380
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-55379
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-54293
A flaw was found in NLTK (Natural Language Toolkit).
highCVSSv3 7.5 - CVE-2026-54283
A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size)…
highCVSSv3 7.5 - CVE-2026-5422
A flaw was found in jupyter-server.
highCVSSv3 8.1 - CVE-2026-54060
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.5 - CVE-2026-54058
A flaw was found in Pillow prior to 12.3.0.
criticalCVSSv3 9.1 - CVE-2026-53550
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
mediumCVSSv3 5.3 - CVE-2026-5241
A flaw was found in python-transformers.
criticalCVSSv3 9.6 - CVE-2026-50193
A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor.
medium - CVE-2026-49978
A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks.
mediumCVSSv3 6.1 - CVE-2026-49851
A flaw was found in Mistune, a Python Markdown parser.
highCVSSv3 7.5 - CVE-2026-49477
A flaw was found in soupsieve, a CSS selector library.
highCVSSv3 7.5 - CVE-2026-49476
A flaw was found in soupsieve, a CSS selector library used with Beautiful Soup 4.
highCVSSv3 7.5 - CVE-2026-48801
A flaw was found in linkify-it, a library for recognizing links with full Unicode support.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-48712
A flaw was found in protobufjs.
highCVSSv3 7.5 - CVE-2026-48710Actively exploited
A flaw was found in Starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework.
criticalCVSSv3 6.5 - CVE-2026-48526
A flaw was found in PyJWT, a Python library for JSON Web Token (JWT) implementation.
highCVSSv3 7.4 - CVE-2026-47214
A flaw was found in Docling, a document processing tool.
highCVSSv3 7.1 - CVE-2026-46625
A flaw was found in JavaScript Cookie (js-cookie).
highCVSSv3 7.5 - CVE-2026-46597
A flaw was found in golang.org/x/crypto/ssh.
highCVSSv3 7.5 - CVE-2026-46595
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 10.0 - CVE-2026-45804
A flaw was found in Diffusers, a library for pretrained diffusion models.
highCVSSv3 7.5 - CVE-2026-45740
A flaw was found in protobufjs.
mediumCVSSv3 5.3 - CVE-2026-45736
A flaw was found in ws, an open source WebSocket client and server for Node.js.
highCVSSv3 7.5 - CVE-2026-45623
A flaw was found in PostCSS, a tool that processes CSS files.
highCVSSv3 7.5 - CVE-2026-45292
A flaw was found in OpenTelemetry Java, specifically within the baggage propagation implementation of opentelemetry-api and opentelemetry…
mediumCVSSv3 5.3 - CVE-2026-44843
A flaw was found in LangChain, a framework for building agents and large language model (LLM)-powered applications.
highCVSSv3 8.2 - CVE-2026-44827
A flaw was found in Diffusers, a library for pretrained diffusion models.
highCVSSv3 8.8 - CVE-2026-44727
A flaw was found in Jupyter Server.
criticalCVSSv3 9.0 - CVE-2026-44724
A flaw was found in systeminformation, a Node.js library.
highCVSSv3 7.8 - CVE-2026-44705
A flaw was found in tmp, a temporary file and directory creator for Node.js.
high - CVE-2026-44660
A flaw was found in UltraJSON, a fast JSON encoder and decoder.
highCVSSv3 7.5 - CVE-2026-44513
A flaw was found in Diffusers, a library for pretrained diffusion models.
highCVSSv3 8.8 - CVE-2026-44496
A flaw was found in Axios.
highCVSSv3 7.5 - CVE-2026-44495
A flaw was found in Axios, a promise-based HTTP client.
highCVSSv3 7.7 - CVE-2026-44494
A flaw was found in Axios.
highCVSSv3 8.7 - CVE-2026-44492
A flaw was found in Axios, a promise-based HTTP client.
highCVSSv3 8.6 - CVE-2026-44488
A flaw was found in Axios, a promise-based HTTP client.
highCVSSv3 7.5 - CVE-2026-44487
A flaw was found in Axios.
highCVSSv3 7.5 - CVE-2026-44486
A flaw was found in Axios, a promise-based HTTP client, specifically in its Node.js HTTP adapter.
highCVSSv3 7.5 - CVE-2026-44293
A flaw was found in protobufjs, a library used to compile protobuf definitions into JavaScript functions.
highCVSSv3 8.8 - CVE-2026-44292
A flaw was found in protobufjs, a library that compiles protobuf definitions into JavaScript functions.
mediumCVSSv3 5.3 - CVE-2026-44291
A flaw was found in protobufjs, a library that compiles protobuf definitions into JavaScript functions.
highCVSSv3 8.1 - CVE-2026-44290
A flaw was found in protobufjs.
highCVSSv3 7.5 - CVE-2026-44289
A flaw was found in protobufjs, a library that compiles protobuf definitions into JavaScript functions.
highCVSSv3 7.5 - CVE-2026-44244
A flaw was found in GitPython, a Python library used to interact with Git repositories.
highCVSSv3 7.8 - CVE-2026-44240
A flaw was found in basic-ftp, an FTP client for Node.js.
highCVSSv3 7.5 - CVE-2026-44020
A flaw was found in docling.
highCVSSv3 7.5 - CVE-2026-44018
A flaw was found in Docling, a tool for document processing.
mediumCVSSv3 5.5 - CVE-2026-44017
A flaw was found in Docling.
highCVSSv3 7.5 - CVE-2026-42557
A flaw was found in jupyterlab.
criticalCVSSv3 9.6 - CVE-2026-42508
A flaw was found in golang.org/x/crypto/ssh/knownhosts.
criticalCVSSv3 9.1 - CVE-2026-42502
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-42499
A flaw was found in the `net/mail` package within the Go standard library.
highCVSSv3 7.5 - CVE-2026-42342
A flaw was found in React Router and @remix-run/server-runtime.
highCVSSv3 7.5 - CVE-2026-42338
A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses.
highCVSSv3 8.1 - CVE-2026-42311
A flaw was found in Pillow, a Python imaging library.
highCVSSv3 7.8 - CVE-2026-42305
A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols.
highCVSSv3 8.8 - CVE-2026-42284
A flaw was found in GitPython, a Python library for interacting with Git repositories.
highCVSSv3 8.1 - CVE-2026-42266
A flaw was found in JupyterLab, an extensible environment for interactive computing.
highCVSSv3 8.8 - CVE-2026-42264
A flaw was found in Axios, a widely used HTTP client.
criticalCVSSv3 9.1 - CVE-2026-42215
A flaw was found in GitPython, a Python library used to interact with Git repositories.
highCVSSv3 8.8 - CVE-2026-42211
A flaw was found in React Router when operating in Framework Mode.
highCVSSv3 8.1 - CVE-2026-41675
A flaw was found in xmldom.
highCVSSv3 7.5 - CVE-2026-41673
A flaw was found in the `xmldom` library, a JavaScript module for parsing XML documents.
highCVSSv3 7.5 - CVE-2026-41672
A flaw was found in xmldom and @xmldom/xmldom, a JavaScript module for parsing and serializing XML.
highCVSSv3 7.5 - CVE-2026-40171
A flaw was found in Jupyter Notebook and JupyterLab.
high - CVE-2026-39835
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 5.3 - CVE-2026-39831
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 9.1 - CVE-2026-39830
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 9.1 - CVE-2026-39829
A flaw was found in golang.org/x/crypto/ssh.
highCVSSv3 7.5 - CVE-2026-39828
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 6.3 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-39820
A flaw was found in the `net/mail` package of the Go programming language.
highCVSSv3 7.5 - CVE-2026-35397
A flaw was found in Jupyter Server.
highCVSSv3 8.8 - CVE-2026-34993
A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python.
highCVSSv3 7.3 - CVE-2026-33814
A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2).
highCVSSv3 7.5 - CVE-2026-33811
A flaw was found in the `net` package of Go (golang), specifically when using the `LookupCNAME` function with the `cgo` DNS resolver.
highCVSSv3 7.5 - CVE-2026-33245
A flaw was found in React Router.
highCVSSv3 8.0 - CVE-2026-33079
A flaw was found in Mistune, a Markdown parser.
highCVSSv3 7.5 - CVE-2026-32283
A flaw was found in the `crypto/tls` package within the Go (golang) standard library, specifically affecting TLS 1.3 connections.
highCVSSv3 7.5 - CVE-2026-32280
A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`.
highCVSSv3 7.5 - CVE-2026-27136
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-2614
A flaw was found in mlflow.
highCVSSv3 7.5 - CVE-2026-25681
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-18982
A flaw was found in the RHOAI training-operator.
highCVSSv3 8.8 - CVE-2026-18951
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator.
highCVSSv3 8.8 - CVE-2026-18948
A flaw was found in Feast.
criticalCVSSv3 9.9 - CVE-2026-18621
A flaw was found in Data Science Pipelines (DSP).
highCVSSv3 7.6 - CVE-2026-18620
A flaw was found in Data Science Pipelines.
highCVSSv3 7.1 - CVE-2026-18617
A flaw was found in the Data Science Pipelines Operator (DSPO).
highCVSSv3 8.8 - CVE-2026-18611
A flaw was found in the Data Science Pipelines Operator.
highCVSSv3 7.5 - CVE-2026-18608
A flaw was found in the Data Science Pipelines Operator (DSPO).
highCVSSv3 8.7 - CVE-2026-16745
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI).
highCVSSv3 8.8 - CVE-2026-15581
A flaw was found in the TrustyAI Service (TAS) deployment.
highCVSSv3 8.0 - CVE-2026-15467
A flaw was found in the trustyai-service-operator's LMEvalJob controller.
highCVSSv3 8.1 - CVE-2026-15378
A flaw was found in the `guardrails-detectors` component.
criticalCVSSv3 9.3 - CVE-2026-15218
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI.
highCVSSv3 7.9 - CVE-2026-15154
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI.
mediumCVSSv3 6.5 - CVE-2026-14450
A flaw was found in the MaaS API.
criticalCVSSv3 9.9 - CVE-2026-13717
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway.
highCVSSv3 8.8 - CVE-2026-13676
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-13311
A flaw was found in the `shell-quote` component.
highCVSSv3 7.5 - CVE-2026-13149
A flaw was found in brace-expansion.
high - CVE-2026-12481
A flaw was found in the Keras deep learning library.
criticalCVSSv3 9.8 - CVE-2026-12243
A flaw was found in NLTK.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2026-0545
A flaw was found in mlflow/mlflow.
criticalCVSSv3 9.8 - CVE-2025-71330
A flaw was found in image-size.
highCVSSv3 7.5 - CVE-2025-71329
A flaw was found in image-size.
highCVSSv3 7.5 - CVE-2025-66626
A path traversal and arbitrary file overwrite vulnerability has been identified in Argo Workflows during the extraction of archived artif…
highCVSSv3 8.1 - CVE-2025-66471
A decompression handling flaw has been discovered in urllib3.
high