What is CVE-2026-18618?
A vulnerability exists in ml-metadata due to an outdated, statically-linked gRPC stack, exposing it to known HTTP/2 denial of service attacks. An in-cluster attacker with network access to the MLMD pod can exploit this by sending crafted HTTP/2 requests, potentially causing service disruption. Updating ml-metadata to a patched version is strongly recommended.
Azərbaycanca: Bu zəiflik ml-metadata komponentində statik əlaqələndirilmiş köhnə gRPC stack səbəbindən yaranır. Şəbəkə üzərindən MLMD pod-a çıxışı olan in-cluster hücumçu, xüsusi hazırlanmış HTTP/2 sorğuları göndərərək xidmət dayandırma (DoS) hücumu həyata keçirə bilər. Ən qısa zamanda ml-metadata versiyasını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
How can CVE-2026-18618 affect the ml-metadata component?
An in-cluster attacker with network access to the MLMD pod can exploit this vulnerability by sending crafted HTTP/2 requests, potentially causing a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.