CVE-2026-15143 CRITICAL

CVE-2026-15143: Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)

Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Weakness CWE-918 · SSRF
Published July 10, 2026
Last update July 10, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

What the vulnerability does

01Description

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.

Key dates

02Disclosure timeline

July 10, 2026 CVE published

Related vulnerabilities

04Related CVE