RHSA-2026:4271HighCVSS 7.6

Red Hat Security Advisory: RHTAS 1.3.2 - Tech Preview Release of Model Transparency

Published
March 11, 2026
Last Modified
June 2, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2025-12638 — keras: Path Traversal Vulnerability in keras CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-0897 — Keras: Keras: Denial of Service via crafted HDF5 weight loading file CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking

🔗 References (11)