CVE-2026-1260

high Red Hat
CVSS v3 Base Score
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: January 22, 2026
Last Modified: January 22, 2026
Vendor: Red Hat

Description

Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.

CWE

CWE-119

Affected Products

Red Hat AI Inference ServerRed Hat Enterprise Linux AI (RHEL AI) 3Red Hat OpenShift AI (RHOAI)Red Hat OpenShift AI 2.25Red Hat OpenShift AI 3.3

Fix Status

✅ Fix Available

References