CVE-2026-18618
Received Received - Intake

Outdated gRPC Stack in ml-metadata HTTP/2 DoS Vulnerability

Vulnerability report for CVE-2026-18618, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could lead to a denial of service by crashing the MLMD pod, disrupting all pipeline runs in the affected namespace.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ml-metadata ml-metadata *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in ml-metadata, where the statically-linked gRPC stack is outdated and vulnerable to known HTTP/2 denial of service (DoS) issues. An attacker within the cluster with network access to the MLMD pod could exploit this by sending specially crafted HTTP/2 requests, causing the pod to crash and disrupting all pipeline runs in the affected namespace.

Detection Guidance

Detecting this vulnerability requires checking for outdated gRPC stacks in ml-metadata deployments. Inspect the ml-metadata pod logs for HTTP/2-related errors or crashes. Use commands like 'kubectl logs <mlmd-pod-name>' to review logs. Additionally, scan network traffic for malformed HTTP/2 requests targeting the MLMD pod.

Impact Analysis

If you use ml-metadata in your environment, an attacker could crash the MLMD pod by exploiting this vulnerability, leading to a denial of service. This would disrupt all pipeline runs in the affected namespace, potentially causing downtime and loss of functionality for machine learning workflows.

Mitigation Strategies

Update the gRPC stack in ml-metadata to a patched version. Restrict network access to the MLMD pod using Kubernetes network policies. Monitor the MLMD pod for crashes or unusual activity. Consider temporarily disabling pipeline runs until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18618. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart