A flaw was found in guardrails-detectors, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openshift_ai | Redhat | - (including) | - (including) |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-built-in-detector-rhel9:1784230964 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-built-in-detector-rhel9:1785137880 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-built-in-detector-rhel9:1783569145 | * |