CVE-2025-12805
Description
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in one namespace can access another user’s Llama Stack instance and potentially view or manipulate sensitive data.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=2413101
Vendor advisory: secalert@redhat.com — https://access.redhat.com/security/cve/CVE-2025-12805
Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2026:2695
Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2026:2106
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | openshift_ai | 2.25 | |
References
CWEs
CWE-653
Verify integrity in audit chain (admin only). AS-IS.