A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data.
History

Thu, 26 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data.
Title llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
First Time appeared Redhat
Redhat openshift Ai
CPEs cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_ai:2.25::el9
Vendors & Products Redhat
Redhat openshift Ai
References

Wed, 04 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-03-26T21:48:16.762Z

Reserved: 2025-11-06T13:48:05.305Z

Link: CVE-2025-12805

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-31T23:59:00Z

Links: CVE-2025-12805 - Bugzilla

cve-icon OpenCVE Enrichment

No data.