CyberzSOC

Applicability
← Back to CVE-2026-42271

CVE-2026-42271

In CISA KEV BerriAI

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-06-30
8 fixed 19 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-10
3 affected 3 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-07-15
1 affected
CVE List v5 (ADP/Vulnrichment)
precedence 55 · revised 2026-07-15
7 not affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (39)

Product Status Versions Remediation Source
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:59a4a3dc01e258bdd6aa463c8dbb34e14bd1a8357ef6ae3d4ea9e6c8ce062353_arm64 registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:59a4a3dc01e258bdd6aa463c8dbb34e14bd1a8357ef6ae3d4ea9e6c8ce062353_arm64 as a component of Red Hat OpenShift AI 2.25 fixed registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:59a4a3dc01e258bdd6aa463c8dbb34e14bd1a8357ef6ae3d4ea9e6c8ce062353_arm64 vendor fix → registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:59a4a3dc01e258bdd6aa463c8dbb34e14bd1a8357ef6ae3d4ea9e6c8ce062353_arm6 (RHSA-2026:28960) csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:66cc80e961fe991b063dc51467fa901dce3fb2afc383afed1c596ec432363022_amd64 registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:66cc80e961fe991b063dc51467fa901dce3fb2afc383afed1c596ec432363022_amd64 as a component of Red Hat OpenShift AI 2.25 fixed registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:66cc80e961fe991b063dc51467fa901dce3fb2afc383afed1c596ec432363022_amd64 vendor fix → registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:66cc80e961fe991b063dc51467fa901dce3fb2afc383afed1c596ec432363022_amd6 (RHSA-2026:28960) csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:b6ec1fac474c9ff596322446656add0ebb10c449d623c37a3f71548957dc4c9c_amd64 registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:b6ec1fac474c9ff596322446656add0ebb10c449d623c37a3f71548957dc4c9c_amd64 as a component of Red Hat OpenShift AI 3.3 fixed registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:b6ec1fac474c9ff596322446656add0ebb10c449d623c37a3f71548957dc4c9c_amd64 vendor fix → registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:b6ec1fac474c9ff596322446656add0ebb10c449d623c37a3f71548957dc4c9c_amd6 (RHSA-2026:30056) csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:ee821288511aaf6e91080f8a925a425e5d26eeacc73f042b39469c65c2e7a139_arm64 registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:ee821288511aaf6e91080f8a925a425e5d26eeacc73f042b39469c65c2e7a139_arm64 as a component of Red Hat OpenShift AI 3.3 fixed registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:ee821288511aaf6e91080f8a925a425e5d26eeacc73f042b39469c65c2e7a139_arm64 vendor fix → registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:ee821288511aaf6e91080f8a925a425e5d26eeacc73f042b39469c65c2e7a139_arm6 (RHSA-2026:30056) csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1c962bba45e5cddaadd8ceff241417f9c3686aba1df8b6b511caf5a9901f2c40_amd64 registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1c962bba45e5cddaadd8ceff241417f9c3686aba1df8b6b511caf5a9901f2c40_amd64 as a component of Red Hat OpenShift AI 3.4 fixed registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1c962bba45e5cddaadd8ceff241417f9c3686aba1df8b6b511caf5a9901f2c40_amd64 vendor fix → registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1c962bba45e5cddaadd8ceff241417f9c3686aba1df8b6b511caf5 (RHSA-2026:27784) csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1d6d4da4451688faa350b05558ed601e5c498b2382923f1bf45fc41958b098f6_s390x registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1d6d4da4451688faa350b05558ed601e5c498b2382923f1bf45fc41958b098f6_s390x as a component of Red Hat OpenShift AI 3.4 fixed registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1d6d4da4451688faa350b05558ed601e5c498b2382923f1bf45fc41958b098f6_s390x vendor fix → registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:1d6d4da4451688faa350b05558ed601e5c498b2382923f1bf45fc4 (RHSA-2026:27784) csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:305bf281a63bff13b96466fb7adfd0962ac28e92d649ad692a86eb10db89a1a0_arm64 registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:305bf281a63bff13b96466fb7adfd0962ac28e92d649ad692a86eb10db89a1a0_arm64 as a component of Red Hat OpenShift AI 3.4 fixed registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:305bf281a63bff13b96466fb7adfd0962ac28e92d649ad692a86eb10db89a1a0_arm64 vendor fix → registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:305bf281a63bff13b96466fb7adfd0962ac28e92d649ad692a86eb (RHSA-2026:27784) csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:5149bc20e5d0a9e281ca3330d000d613b5987f46996e771067532af0fe3e0fb8_ppc64le registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:5149bc20e5d0a9e281ca3330d000d613b5987f46996e771067532af0fe3e0fb8_ppc64le as a component of Red Hat OpenShift AI 3.4 fixed registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:5149bc20e5d0a9e281ca3330d000d613b5987f46996e771067532af0fe3e0fb8_ppc64le vendor fix → registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9@sha256:5149bc20e5d0a9e281ca3330d000d613b5987f46996e771067532a (RHSA-2026:27784) csaf_redhat
red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9 ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2 not affected vulnerable code not in execute path ansible-automation-platform-26/lightspeed-chatbot-rhel9 not applicable csaf_redhat
red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9 ansible-automation-platform-27/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2 not affected vulnerable code not in execute path ansible-automation-platform-27/lightspeed-chatbot-rhel9 not applicable csaf_redhat
exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence not affected vulnerable code not in execute path exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 not applicable csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-operator-bundle@sha256:0efd1bb73b277b4cdca47bcb424679de6fd094d04e73e7a3ed0c470e8040b440_amd64 registry.redhat.io/rhoai/odh-operator-bundle@sha256:0efd1bb73b277b4cdca47bcb424679de6fd094d04e73e7a3ed0c470e8040b440_amd64 as a component of Red Hat OpenShift AI 3.4 not affected vulnerable code not present registry.redhat.io/rhoai/odh-operator-bundle@sha256:0efd1bb73b277b4cdca47bcb424679de6fd094d04e73e7a3ed0c470e8040b440_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-operator-bundle@sha256:163f636a1cbc151572ad0470bd5b06650980efd72e6c462cff6ce9ce4bcfaa93_amd64 registry.redhat.io/rhoai/odh-operator-bundle@sha256:163f636a1cbc151572ad0470bd5b06650980efd72e6c462cff6ce9ce4bcfaa93_amd64 as a component of Red Hat OpenShift AI 3.3 not affected vulnerable code not present registry.redhat.io/rhoai/odh-operator-bundle@sha256:163f636a1cbc151572ad0470bd5b06650980efd72e6c462cff6ce9ce4bcfaa93_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-operator-bundle@sha256:c0d7ed557a77e880b7d78eb3a87a05cadaf8711eea4e024fece782f5a68edebe_amd64 registry.redhat.io/rhoai/odh-operator-bundle@sha256:c0d7ed557a77e880b7d78eb3a87a05cadaf8711eea4e024fece782f5a68edebe_amd64 as a component of Red Hat OpenShift AI 2.25 not affected vulnerable code not present registry.redhat.io/rhoai/odh-operator-bundle@sha256:c0d7ed557a77e880b7d78eb3a87a05cadaf8711eea4e024fece782f5a68edebe_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:195a25181e1ff5c73cea1146a339489398cb54618e8cd9d574e90a72a1ff3e11_arm64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:195a25181e1ff5c73cea1146a339489398cb54618e8cd9d574e90a72a1ff3e11_arm64 as a component of Red Hat OpenShift AI 3.3 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:195a25181e1ff5c73cea1146a339489398cb54618e8cd9d574e90a72a1ff3e11_arm64 not applicable csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:1fc8714e90d4b7a9ca8e6d9360f692fee9a764d6e556d5241886dbf116df8902_arm64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:1fc8714e90d4b7a9ca8e6d9360f692fee9a764d6e556d5241886dbf116df8902_arm64 as a component of Red Hat OpenShift AI 2.25 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:1fc8714e90d4b7a9ca8e6d9360f692fee9a764d6e556d5241886dbf116df8902_arm64 not applicable csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:227cecaf494ed3999aee9743b93371bd11eebce31538d34bea239133f473e3dd_s390x registry.redhat.io/rhoai/odh-rhel9-operator@sha256:227cecaf494ed3999aee9743b93371bd11eebce31538d34bea239133f473e3dd_s390x as a component of Red Hat OpenShift AI 2.25 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:227cecaf494ed3999aee9743b93371bd11eebce31538d34bea239133f473e3dd_s390x not applicable csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:48a73c9e0491f2f9bb109e15fea89ebd65939ed9bcfced506e006f23bbe9f64e_ppc64le registry.redhat.io/rhoai/odh-rhel9-operator@sha256:48a73c9e0491f2f9bb109e15fea89ebd65939ed9bcfced506e006f23bbe9f64e_ppc64le as a component of Red Hat OpenShift AI 3.3 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:48a73c9e0491f2f9bb109e15fea89ebd65939ed9bcfced506e006f23bbe9f64e_ppc64le not applicable csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:4b8e9cda02c30b95aa6e483dd9f90b2e27b9093212c6c3d956be8da3dd00dd16_s390x registry.redhat.io/rhoai/odh-rhel9-operator@sha256:4b8e9cda02c30b95aa6e483dd9f90b2e27b9093212c6c3d956be8da3dd00dd16_s390x as a component of Red Hat OpenShift AI 3.4 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:4b8e9cda02c30b95aa6e483dd9f90b2e27b9093212c6c3d956be8da3dd00dd16_s390x not applicable csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5b0afdcb5c35d4c55847e1eb2967056ef9f508549f40028d6a6d2b41f6e70fe6_amd64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5b0afdcb5c35d4c55847e1eb2967056ef9f508549f40028d6a6d2b41f6e70fe6_amd64 as a component of Red Hat OpenShift AI 3.3 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5b0afdcb5c35d4c55847e1eb2967056ef9f508549f40028d6a6d2b41f6e70fe6_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5d74f4badc192e18e4cf8027a2091cf5148f1426e0542bc5d7a5ecaf6dd9cf87_ppc64le registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5d74f4badc192e18e4cf8027a2091cf5148f1426e0542bc5d7a5ecaf6dd9cf87_ppc64le as a component of Red Hat OpenShift AI 2.25 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:5d74f4badc192e18e4cf8027a2091cf5148f1426e0542bc5d7a5ecaf6dd9cf87_ppc64le not applicable csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:72648350ddd7a3401542e90f923df38adb4ee75ded438dade1bc472566f474dc_ppc64le registry.redhat.io/rhoai/odh-rhel9-operator@sha256:72648350ddd7a3401542e90f923df38adb4ee75ded438dade1bc472566f474dc_ppc64le as a component of Red Hat OpenShift AI 3.4 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:72648350ddd7a3401542e90f923df38adb4ee75ded438dade1bc472566f474dc_ppc64le not applicable csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:76341c99cdb9a4321a37a58b1757ed0327bcf8d3adfa5688109f138a16b5ef04_amd64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:76341c99cdb9a4321a37a58b1757ed0327bcf8d3adfa5688109f138a16b5ef04_amd64 as a component of Red Hat OpenShift AI 3.4 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:76341c99cdb9a4321a37a58b1757ed0327bcf8d3adfa5688109f138a16b5ef04_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 2.25:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:a2362d90bb91fd360fdbfe760206da6a30024cca09b9839bdbfe0573a3e76ace_amd64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:a2362d90bb91fd360fdbfe760206da6a30024cca09b9839bdbfe0573a3e76ace_amd64 as a component of Red Hat OpenShift AI 2.25 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:a2362d90bb91fd360fdbfe760206da6a30024cca09b9839bdbfe0573a3e76ace_amd64 not applicable csaf_redhat
Red Hat OpenShift AI 3.4:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:cc6f060d37c92ea68c955e637e6291863272c1992ba86bc872989c4b566fc8bf_arm64 registry.redhat.io/rhoai/odh-rhel9-operator@sha256:cc6f060d37c92ea68c955e637e6291863272c1992ba86bc872989c4b566fc8bf_arm64 as a component of Red Hat OpenShift AI 3.4 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:cc6f060d37c92ea68c955e637e6291863272c1992ba86bc872989c4b566fc8bf_arm64 not applicable csaf_redhat
Red Hat OpenShift AI 3.3:registry.redhat.io/rhoai/odh-rhel9-operator@sha256:f7788f465a7f7d03b8ac7b1de0994e99eb95693f78120856420e7d2426a3c466_s390x registry.redhat.io/rhoai/odh-rhel9-operator@sha256:f7788f465a7f7d03b8ac7b1de0994e99eb95693f78120856420e7d2426a3c466_s390x as a component of Red Hat OpenShift AI 3.3 not affected vulnerable code not present registry.redhat.io/rhoai/odh-rhel9-operator@sha256:f7788f465a7f7d03b8ac7b1de0994e99eb95693f78120856420e7d2426a3c466_s390x not applicable csaf_redhat
red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9 rhoai/odh-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI) not affected vulnerable code not in execute path rhoai/odh-mlflow-rhel9 not applicable csaf_redhat
https://github.com/berriai/litellm affected >= 225e9f3d552d190a3042f1081bcc17e6f599d151, < e0d5c28db02b3219dbd944666a55f49732197922 vendor fix → e0d5c28db02b3219dbd944666a55f49732197922 osv
litellm affected >= 1.74.2, < 1.83.7 vendor fix → 1.83.7 osv GHSA-v4p8-mg3p-g94g
https://github.com/berriai/litellm fixed e0d5c28db02b3219dbd944666a55f49732197922 vendor fix → e0d5c28db02b3219dbd944666a55f49732197922 osv
litellm fixed 1.83.7 vendor fix → 1.83.7 osv GHSA-v4p8-mg3p-g94g
BerriAI/litellm BerriAI · litellm affected >= 1.74.2, < 1.83.7 none available cve_cna
Red Hat/Exploit Intelligence/exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 Red Hat · Exploit Intelligence not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Ansible Automation Platform 2/ansible-automation-platform-26/lightspeed-chatbot-rhel9 Red Hat · Red Hat Ansible Automation Platform 2 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat Ansible Automation Platform 2/ansible-automation-platform-27/lightspeed-chatbot-rhel9 Red Hat · Red Hat Ansible Automation Platform 2 not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat OpenShift AI (RHOAI)/rhoai/odh-mlflow-rhel9 Red Hat · Red Hat OpenShift AI (RHOAI) not affected no version stated vendor label: all versions not applicable cve_adp
Red Hat/Red Hat OpenShift AI 2.25/rhoai/odh-llama-stack-core-rhel9 Red Hat · Red Hat OpenShift AI 2.25 not affected 1781826406 not applicable cve_adp
Red Hat/Red Hat OpenShift AI 3.3/rhoai/odh-llama-stack-core-rhel9 Red Hat · Red Hat OpenShift AI 3.3 not affected 1782310008 not applicable cve_adp
Red Hat/Red Hat OpenShift AI 3.4/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 Red Hat · Red Hat OpenShift AI 3.4 not affected 1781622627 not applicable cve_adp

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.