VYPR

trustyai-service-operator

by Red Hat

CVEs (2)

  • CVE-2026-15467HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote…

  • CVE-2026-15063MedJul 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these…