CVE-2026-32640

Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI

criticalEPSS 0.5 %

Beschreibung

SimpleEval ist eine Bibliothek zum Hinzufügen auswertbarer Ausdrücke zu Python-Projekten. Vor Version 1.0.5 können Objekte (einschließlich Module) gefährliche Module in den direkten Zugriff innerhalb der Sandbox durchsickern lassen. Wenn die von Ihnen an SimpleEval übergebenen Objekte als Namen verfügbare Module oder andere nicht erlaubte / gefährliche Objekte als Attribute haben, besteht dieses Risiko. Zusätzlich könnten gefährliche Funktionen oder Module durch das Übergeben als Callbacks zu anderen sicheren Funktionen aufgerufen werden. Die neueste Version 1.0.5 hat dieses Problem behoben. Diese Schwachstelle ist in der Version 1.0.5 behoben.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
42.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-09 11:57 UTC
CWE-915, CWE-94

Weakness-Klassen (CWE)

  • CWE-915Base

    Improperly Controlled Modification of Dynamically-Determined Object Attributes

    The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

    cwe.mitre.org →
  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux_ai3.0

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • aiohttp

    aiohttp3.13.3

  • aiohttp

    aiohttp3.14.0

  • bitnami

    mlflow

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • danthedeckie

    simpleeval1.0.5

  • encode

    starlette0.8.3 – 1.0.1

  • golang

    crypto0.52.0

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • grpc

    grpc1.79.3

  • huggingface

    transformers

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • keras

    keras

  • langchain

    langchain_core1.2.22

  • nltk

    nltk3.9.3

  • protobufjs_project

    protobufjs7.5.5

  • protobufjs_project

    protobufjs

  • pyasn1

    pyasn10.6.2

  • pyasn1

    pyasn10.6.3

  • pyjwt_project

    pyjwt2.12.0

  • pyjwt_project

    pyjwt2.13.0

  • pypa

    pip26.1.2

  • pypi

    multipart0.1

Quellen & Referenzen

Verknüpfte CVEs

7 weitere CVEs anzeigen
IDCVE-2026-32640