VYPR

Data Science Pipelines Operator

by Red Hat

CVEs (3)

  • CVE-2026-18617HigAug 10, 2026
    risk 0.57cvss 8.8epss

    A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these…

  • CVE-2026-18608HigAug 10, 2026
    risk 0.57cvss 8.7epss

    A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods…

  • CVE-2026-18611HigAug 10, 2026
    risk 0.49cvss 7.5epss

    A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw…