A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-15154 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498188 | Issue Tracking Vendor Advisory |
Configurations
History
10 Jul 2026, 15:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat openshift Ai
Redhat |
|
| CPE | cpe:2.3:a:redhat:openshift_ai:-:*:*:*:*:*:*:* | |
| References | () https://access.redhat.com/security/cve/CVE-2026-15154 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2498188 - Issue Tracking, Vendor Advisory |
08 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 20:16
Updated : 2026-07-10 15:24
NVD link : CVE-2026-15154
Mitre link : CVE-2026-15154
CVE.ORG link : CVE-2026-15154
JSON object : View
Products Affected
redhat
- openshift_ai
CWE
CWE-1333
Inefficient Regular Expression Complexity
