Bug 2498058 (CVE-2026-15063)

Summary: CVE-2026-15063 trustyai-service-operator: TrustyAI Service Operator: Gorch port bypass when auth IS enabled
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-08 14:34:19 UTC
The gorch service template (gorch/templates/service.tmpl.yaml:27-32) publishes https-tls: 8032->8032 (unproxied orchestrator) and built-in-detector-metrics: 8080->8080 alongside the proxied ports, even when auth is enabled. The root cause is gorch/auth.go:30 which configures kube-rbac-proxy upstream as %s-service.%s.svc:8032 (Service DNS), architecturally requiring port 8032 to remain on the Service. Any pod on the cluster network can bypass kube-rbac-proxy by hitting port 8032 directly.

By contrast, NemoGuardrails properly switches to proxied-only ports when auth is enabled. EvalHub always deploys with kube-rbac-proxy and API_HOST=127.0.0.1 loopback binding, proving auth-by-default is architecturally achievable.

No NetworkPolicy exists anywhere in the codebase (grep returns zero results).

Gorch port bypass (even with auth enabled):
1. Enable auth on gorch via annotation
2. kube-rbac-proxy is deployed on port 8443
3. Port 8032 (orchestrator) and 8080 (detector metrics) remain exposed on the Service
4. Any pod hits port 8032 directly, bypassing kube-rbac-proxy