Database/AI/ML frameworks & serving
AI/ML framework and model serving vulnerabilities
CVEs and advisories in inference servers, training frameworks, and model formats: Triton, vLLM, TorchServe, Ray, MLflow, Jupyter, and the rest of the tenant-facing AI layer. On shared GPU infrastructure these are the bugs a tenant can reach first.
269 entries92 critical3 known exploitedFilter and search this layer
2026
llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`HighAug 6, 2026
llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsHighAug 6, 2026
llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplicationHighAug 6, 2026- Milvus: Unauthenticated DoS terminating service componentsHighAug 5, 2026
SGLang (`/load_lora_adapter_from_tensors`): Unauthenticated RCE bypassing `SafeUnpickler`'s incomplete denylistCriticalJul 30, 2026
SGLang (`/server_info`): Endpoint returns API keys and SSL keyfile pathsHighJul 30, 2026
SGLang (weight exfiltration): Two endpoints allow a remote attacker to pull model weights when no API key is setHighJul 30, 2026- torchvision (GIF decoder): Out-of-bounds heap read in `read_from_tensor` GIF decodeHighJul 23, 2026
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`MediumJul 23, 2026
Kubeflow Community Distribution: Insecure default in the platform installHighJul 21, 2026- Ollama (GGUF metadata parser): Uncontrolled memory allocationHighJul 21, 2026
- Keras (`TorchModuleWrapper`): Unsafe deserialization of attacker-controlled PyTorch pickle inside a Keras modelHighJul 19, 2026
SGLang (expert-parallel backup ZMQ PULL): Unauthenticated, unvalidated deserialization on a routable interfaceCriticalJul 16, 2026- Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpointHighJul 16, 2026
LiteLLM (MCP server creation): RCE via MCP server registrationCriticalJul 15, 2026- PyTorch Lightning (`_load_state`): RCE by importing and executing classes named in the checkpointHighJul 15, 2026
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityLowJul 13, 2026
- TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIsMediumJul 8, 2026
LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLsHighJul 7, 2026- Keras (Lambda layer): Arbitrary code execution via Lambda-layer deserialization in 3.14.0CriticalJul 3, 2026
Weaviate: RBAC role assignment does not verify the assigner holds the granted permissionsHighJul 2, 2026- Ray (WebDataset reader): Unsafe deserializationHighJul 1, 2026
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readMediumJul 1, 2026
- Ollama (quantization engine): Unauthenticated remote information disclosure — reads and exfiltrates model dataHighJun 26, 2026
LiteLLM proxy: Host-header parsing flaw in the proxyCriticalJun 22, 2026- vLLM (activation function loading): Assert-based security check bypass, unauthenticatedHighJun 22, 2026
- vLLM (revision pinning): Revision pinning does not apply to all model artifactsMediumJun 22, 2026
- vLLM - sampling parameter validation: Temperature validation uses strict comparison operators, so boundary values slipMediumJun 22, 2026
- vLLM (sparse tensor validation): Missing sparse-tensor invariant checks in multimodal embeddingsHighJun 20, 2026
- picklescan: `scan_pytorch` bypass via forged magic numbersHighJun 17, 2026
stable-diffusion.cpp: Memory-safety flaw in model loadingHighJun 16, 2026
ChromaDB (SimpleRBAC): Authorization provider evaluates permissions incorrectlyHighJun 12, 2026
ChromaDB (V1 endpoints): Tenant/database passed as `None` to the authz layerHighJun 12, 2026
ChromaDB: Authenticated code injectionHighJun 12, 2026
ChromaDB (Rust): Missing authorization validationHighJun 12, 2026- Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`HighJun 11, 2026
- vLLM (hardcoded `trust_remote_code=True`): Two model implementation files force remote code execution regardlessHighMay 28, 2026
- BentoML (`bentofile.yaml`): Malicious build manifestHighMay 27, 2026
- HuggingFace transformers: Critical RCE in all versions before 5.3.0HighMay 24, 2026
- Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandboxHighMay 22, 2026
LiteLLM (key generation): internal_user can mint keys with routes their role forbidsHighMay 21, 2026
LiteLLM (`/user/update`): User can self-elevate `user_role`HighMay 21, 2026
ChromaDB: Pre-authentication code injectionCriticalMay 18, 2026
SGLang (scheduler ROUTER socket): ROUTER socket binds `0.0.0.0` by default and `pickle.loads()` incoming messagesCriticalMay 18, 2026
SGLang (custom logit processor): `dill.loads` on user objects when `--enable-custom-logit-processor` is setCriticalMay 18, 2026
SGLang (multimodal runtime): Unauthenticated path traversalCriticalMay 18, 2026- PyTorch Lightning: Reintroduced unsafe deserialization in 2.6.2CriticalMay 14, 2026
Kubeflow (ART component): RCE in the robustness evaluation functionCriticalMay 12, 2026
Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading componentCriticalMay 12, 2026
LiteLLM proxy: SQL injection in a database query pathCriticalMay 8, 2026- Ray Data (Arrow extension types): Custom Arrow extension types deserialized unsafelyHighMay 8, 2026
LiteLLM proxy: Two endpoints allow privilege escalation / unauthorized actionHighMay 8, 2026
Dagster: Vulnerability in Dagster Core prior to 1.13.1HighMay 7, 2026- Jupyter Server: Path traversal in the REST APIHighMay 5, 2026
- Jupyter Server (Origin validation): `re.match` used for Origin validationHighMay 5, 2026
- Ollama (GGUF model loader): Heap out-of-bounds read from an attacker-supplied GGUF via `/api/create`CriticalMay 4, 2026
SGLang (`/v1/rerank`): RCE via a malicious `tokenizer.chat_template` rendered as Jinja2CriticalApr 20, 2026
LiteLLM (`/guardrails/test_custom_code`): RCE via bytecode rewritingHighApr 10, 2026- HuggingFace transformers (`Trainer._load_rng_state`): Arbitrary code execution when a training run resumesHighApr 7, 2026
LiteLLM (JWT auth): Auth bypass when `enable_jwt_auth` is setCriticalApr 6, 2026
LiteLLM (`/config/update`): Endpoint does not enforce admin authorizationHighApr 6, 2026- BentoML (Dockerfile generation): Injection into generated DockerfileHighApr 6, 2026
- KubeAI (Ollama engine controller): Injection in `ollamaStartupProbeScript()`HighApr 6, 2026
- MLflow (jobs API): `/ajax-api/3.0/jobs/*` unauthenticated even with basic-auth enabledCriticalApr 3, 2026
- JupyterHub OAuthenticator: Authenticated user bypasses the intended identity checkHighApr 3, 2026
llama.cpp (RPC `deserialize_tensor`): RPC backend skips all bounds validationCriticalApr 1, 2026- ONNX (`ExternalDataInfo`): Security control bypass in external-data path handlingHighApr 1, 2026
- vLLM (hardcoded `trust_remote_code`, second instance): Same class, two more model files, through 0.18.0HighMar 27, 2026
- BentoML (`docker.system_packages`): Command injection through the package list fieldHighMar 27, 2026
llama.cpp (`ggml_nbytes`): Integer overflow in the core ggml size calculationHighMar 24, 2026- ONNX: Security-control bypass through 1.20.1HighMar 18, 2026
- Ray Dashboard: Path traversal in the dashboard static-file handler (port 8265)HighMar 17, 2026
SGLang (multimodal ZMQ broker): Unauthenticated RCE via `pickle.loads()` on the ZMQ brokerCriticalMar 12, 2026
SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation moduleCriticalMar 12, 2026
SGLang (`replay_request_dump.py`): Insecure `pickle.load()` on a `.pkl` dumpHighMar 12, 2026- vLLM (`load_from_url_async`): Bypass of the CVE-2026-24779 SSRF fixHighMar 9, 2026
- BentoML (`safe_extract_tarfile`): Tar extraction escape despite the "safe" helperHighMar 3, 2026
- Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETEMediumFeb 21, 2026
- MLflow (artifact handler): Directory traversalHighFeb 20, 2026
- Milvus (port 9091): Management port 9091 exposed by default enabling compromiseCriticalFeb 13, 2026
- Keras (HDF5 external links): Arbitrary local file read during model loadHighFeb 11, 2026
- Qdrant (`/logger`): Append to arbitrary files via the logger endpointHighFeb 6, 2026
- vLLM (image error echo): Error path returns sensitive content on invalid image inputCriticalFeb 2, 2026
- PyTorch (`weights_only` unpickler): Bypass of the `weights_only` allowlistHighJan 27, 2026
- vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242HighJan 27, 2026
- vLLM (HF `auto_map`): Loads Hugging Face dynamic modules during model resolutionHighJan 21, 2026
- Dask distributed (+ Jupyter proxy): Exposure when Dask, JupyterLab and jupyter-server-proxy are combinedMediumJan 16, 2026
Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py): The ART Kubeflow evaluationCritical2026- BentoML (cloud deployment path, setup.sh generation in deployment.py): The March fix that added shlex.quote to theHigh2026
- BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the buildMedium2026
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedMedium2026
2025
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetHighJul 4, 2026
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetHighJun 25, 2026
- MLflow (`extract_archive_to_dir`): Path traversal in the dbconnect artifact cacheCriticalMar 30, 2026
- MLflow (serving container init): Command injection in `_install_model_dependencies`CriticalMar 30, 2026
- MLflow (pyfunc tar extraction): Arbitrary file write from crafted tar entriesCriticalMar 18, 2026
- Linux i915 GPU kernel driver (execbuffer VMA array): MULTI-TENANT ISOLATION: The execbuffer VMA arrayHighJan 14, 2026
- MLflow (REST API): DNS rebinding — no Origin header validationHighJan 12, 2026
- Ollama (API auth): Critical authentication bypass on API endpoints through v0.12.3CriticalDec 18, 2025
- nbconvert: Template-driven conversion executes attacker contentHighDec 17, 2025
Weaviate: Crafted entry name with an absolute pathHighDec 12, 2025
Portkey AI Gateway: Gateway resolves the destination baseURL from attacker-controlled precedenceCriticalDec 1, 2025- vLLM (`Nemotron_Nano_VL_Config`): RCE via a config class evaluated at model loadHighDec 1, 2025
- Keras (`utils.get_file`): Path traversal in tar extraction in 3.11.3 (incomplete fix)HighNov 28, 2025
- vLLM (multimodal embeddings): Memory corruptionHighNov 21, 2025
- Milvus: Unauthenticated attacker exploits the server directlyCriticalNov 10, 2025
- Keras (`utils.get_file`, tar extract): Path traversal on tar extractionHighOct 30, 2025
- MLflow (auth): Weak password requirementsCriticalOct 29, 2025
- MLflow (model creation): Directory traversal on model creationCriticalOct 29, 2025
- Keras: Deserialization of untrusted data in 3.11.0–3.11.2CriticalOct 17, 2025
- vLLM (API key comparison): Timing attack recovers the API keyHighOct 7, 2025
- vLLM (`MediaConnector` SSRF): SSRF via `load_from_url` in multimodal input handlingHighOct 7, 2025
- Red Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromiseCriticalSep 30, 2025
KServe ModelMesh: Group-writable `/etc/passwd` in the container imageMediumSep 30, 2025
llama-index-core: Predictable hardcoded cache directoryHighSep 27, 2025- PyTorch (`torch.linalg.lu`): DoS on slice operationHighSep 25, 2025
- PyTorch (KV/conv path buffer overflow): Buffer overflow when a model combines Conv2d + hardshrink + viewHighSep 25, 2025
- Keras (HDF5 path): Code execution from crafted `.h5`/`.hdf5` model despite safe modeHighSep 19, 2025
- Keras: Code execution from crafted `.keras` archive despite safe modeHighSep 19, 2025
- NVIDIA Triton Inference Server (Python backend): Attacker-controlled input in the Python backendCriticalSep 17, 2025
- picklescan: Improper input validation lets a crafted pickle evade scanningHighSep 17, 2025
SGLang (`/update_weights_from_tensor`): Unsafe deserialization of the `serialized_named_tensors` argumentHighSep 9, 2025- vLLM (HTTP GET): Single HTTP GET crashes the serverHighAug 21, 2025
- Keras: Safe-mode bypass in Keras 3.0.0–3.10.0HighAug 11, 2025
- skops (`Card.get_model`): Model card loading has no trusted-types checkHighAug 8, 2025
- NVIDIA Triton: Stack buffer overflowCriticalAug 6, 2025
- NVIDIA Triton: Stack overflow via crafted requestCriticalAug 6, 2025
- NVIDIA Triton (HTTP server): Attacker can start a reverse shell from the HTTP serverCriticalAug 6, 2025
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendHighAug 6, 2025
- NVIDIA Triton (Python backend shared memory): Out-of-bounds write in the Python backendHighAug 6, 2025
- NVIDIA Triton (Python backend): Information disclosure from the Python backendHighAug 6, 2025
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`MediumAug 6, 2025
- BentoML (file upload): SSRF in the file-upload pathCriticalJul 29, 2025
- skops (scikit-learn model sharing): Inconsistency in the `Operator` handling lets an untrusted model bypass the safeHighJul 26, 2025
- skops: Method-handling inconsistencyHighJul 26, 2025
- ONNX (`save_external_data`): Path traversalHighJul 22, 2025
Dagster (gRPC `get_notebook_data`): Local file inclusion — read arbitrary filesMediumJul 22, 2025
llama.cpp (`gguf_init_from_file_impl`): Integer overflow in GGUF initHighJul 10, 2025
llama.cpp (vocab): Attacker-supplied GGUF vocabulary triggers memory corruptionHighJun 17, 2025
LlamaIndex (vector store integrations): SQL injection across multiple vector store integrationsCriticalJun 5, 2025- Jupyter Core (Windows): Config read from a shared writable pathHighJun 3, 2025
- vLLM (`/v1/completions` guided decoding): Invalid `json_schema` kills the serverMediumMay 30, 2025
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsLowMay 29, 2025
LlamaIndex CLI: OS command injection via the `--files` argumentHighMay 28, 2025- vLLM (`PyNcclPipe` KV transfer): RCE via the KV cache transfer integrationCriticalMay 20, 2025
- vLLM (multi-node ZeroMQ): Secondary vLLM host trusts unauthenticated ZeroMQ messagesHighMay 6, 2025
- vLLM (Mooncake ZMQ/TCP): Unsafe deserialization exposed on all interfacesCriticalApr 30, 2025
- vLLM (ZeroMQ): DoS and data exposure over ZeroMQHighApr 30, 2025
- PyTorch (`torch.load`): RCE via unsafe deserialization even with `weights_only=True`CriticalApr 18, 2025
- BentoML: Insecure deserialization RCE prior to 1.4.8CriticalApr 9, 2025
- BentoML: RCE via insecure deserializationCriticalApr 4, 2025
- Ollama (GGUF import): Crafted GGUF causes DoS on model createHighMar 20, 2025
- vLLM (Mooncake): Unsafe deserialization over ZMQ/TCP bound to all interfacesCriticalMar 19, 2025
- Keras (`Model.load_model`): Arbitrary code execution from a crafted `.keras` archive even with `safe_mode=True`CriticalMar 11, 2025
- picklescan (model scanner): Scanner fails to detect malicious pickles when ZIP flag bits are flippedCriticalMar 10, 2025
- picklescan: ZIP manipulation crashes the scanner (scan bypass by DoS)MediumMar 10, 2025
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesLowFeb 7, 2025
- vLLM (weight loading): `hf_model_weights_iterator` uses `torch.load` without `weights_only`HighJan 27, 2025
- Ray (dashboard job submission API, browser-origin guard): MULTI-TENANT ISOLATION: Ray's only defense againstCritical2025
- Pure Storage FlashArray authentication input validation: Malformed input during authentication takes the FlashArrayHigh2025
- BentoML 1.3.9 (bundled Gradio app, /login endpoint): The /login endpoint of the integrated Gradio app processes eachHigh2025
- Ray (GCS Redis credential handling / logging): MULTI-TENANT ISOLATION: When the Redis password is passed on the RayMedium2025
- BentoML 1.3.9 (open redirect in the serving UI): A crafted URL against the BentoML server bounces the visitor to anMedium2025
- Pure Storage FlashArray key rotation logging (Rapid Data Locking): The Key Encryption Key is written to logs duringMedium2025
2023
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sLowSep 6, 2025
Dagster (webserver): Directory traversalHighJul 7, 2025- Gradio: Command injectionHighDec 14, 2023
Kubeflow: SSRFMediumDec 14, 2023- Ray (job submission API): Unauthenticated RCE — the Jobs API accepts arbitrary code by designCriticalNov 28, 2023
- Ray (`/log_proxy`): SSRF from the dashboardCriticalNov 28, 2023
- TorchServe (model/workflow API): Information disclosure of files on the serving hostMediumNov 21, 2023
- MLflow: Arbitrary account creation bypassing authenticationCriticalNov 16, 2023
- MLflow: Overwrite any file on the MLflow host without authenticationCriticalNov 16, 2023
- Ray (dashboard `cpu_profile`): Command injectionCriticalNov 16, 2023
- Ray (log API): LFI — read any file on the head node, unauthenticatedHighNov 16, 2023
- LangChain (recursive URL loader): SSRF — crawling proceeds to internal hostsHighOct 19, 2023
- langchain-experimental (PALChain): Bypass of the CVE-2023-36258 fixCriticalOct 9, 2023
- TorchServe: Unauthenticated SSRFCriticalSep 28, 2023
- LangChain (`load_prompt`): Arbitrary code execution from a JSON prompt fileCriticalAug 22, 2023
- MLflow: Absolute path traversal prior to 2.5.0CriticalJul 19, 2023
- LangChain (PALChain): Arbitrary code execution via `os.system`/`exec` in generated codeCriticalJul 3, 2023
- Gradio: Lack of path filteringHighJun 8, 2023
- MLflow: Path traversal prior to 2.3.1CriticalMay 17, 2023
- LangChain (`LLMMathChain`): Prompt injectionCriticalApr 5, 2023
- MLflow (tracking server): Path traversal (`\..\filename`)CriticalMar 24, 2023
- Ray (dashboard /static/ file handler): MULTI-TENANT ISOLATION: Path traversal under the dashboard's /static/ route letsCritical2023
- Pure Storage FlashArray VASA provider: MULTI-TENANT ISOLATION: a vSphere or ESXi administrator with VASA access to aHigh2023
2022
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsMediumMay 1, 2025
- ONNX: Directory traversal via `external_data` field in the tensor protoHighJan 26, 2023
- PyTorch (`torch.jit.annotations.parse_type_line`): Arbitrary code execution via unsafe `eval` in TorchScript typeCriticalNov 26, 2022
- joblib: Arbitrary code execution via `eval` on the `pre_dispatch` flag in `Parallel()`HighSep 26, 2022
2024
- vLLM (MessageQueue / ZMQ): `pickle.loads` on socket dataCriticalMar 20, 2025
- vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypointsCriticalMar 20, 2025
- BentoML (runner server): Deserialization RCE on the internal runner serverCriticalMar 20, 2025
- ONNX (`download_model`): Arbitrary file overwriteCriticalMar 20, 2025
LiteLLM: Unauthenticated DoS via `ast.literal_eval` on user inputHighMar 20, 2025- OpenLLM: Local file inclusion via the web applicationMediumMar 20, 2025
- Weights & Biases OpenUI: Unauthenticated endpoints allow file upload and downloadMediumFeb 10, 2025
- MLflow (`spark_udf` dir perms): Excessive directory permissionsHighNov 25, 2024
Kubeflow (Pipelines UI): Stored XSS in the pipeline viewMediumNov 18, 2024- Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)HighOct 31, 2024
- Ollama: File-existence disclosure via `api/create`HighOct 31, 2024
- Ollama: Path traversal in `api/push` discloses server filesystem layoutHighOct 31, 2024
- PyTorch (`torch.distributed` RemoteModule / RPC): Deserialization RCE across the distributed RPC channelCriticalOct 29, 2024
- Gradio: SSRF from the file-upload/proxy pathCriticalOct 10, 2024
- Gradio: CORS origin validation bypassHighOct 10, 2024
LocalAI: RCE — the backend accepts inputs beyond the config pathHighSep 27, 2024- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CriticalSep 19, 2024
- LangChain (`FAISS.deserialize_from_bytes`): Pickle deserialization of an untrusted vector indexHighSep 17, 2024
- Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directoryHighAug 29, 2024
- JupyterLab: XSS via untrusted notebook contentHighAug 28, 2024
llama.cpp (RPC backend): Unsafe `data` pointer in `rpc_tensor`CriticalAug 12, 2024
llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`MediumAug 12, 2024- JupyterHub: A user granted limited access can escalateHighAug 8, 2024
- TorchServe: `allowed_urls` bypassCriticalJul 19, 2024
- TorchServe (gRPC 7070/7071): gRPC ports bound to all interfaces regardless of configHighJul 19, 2024
LocalAI (`/models/apply`): SSRF and partial local file inclusionMediumJul 6, 2024- Gradio: Code injection via `gradio/component_meta.py`CriticalJul 1, 2024
- langchain-experimental (Python REPL): Python REPL exposed without an opt-inHighJun 16, 2024
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCriticalJun 11, 2024
- PyTorch Lightning: RCE via deserialization of untrusted checkpointCriticalJun 6, 2024
- ONNX (`download_model_with_test_data`): Arbitrary file overwrite from a crafted model archiveHighJun 6, 2024
- Gradio (`/queue/join`): SSRFHighJun 6, 2024
LiteLLM: Arbitrary file deletion via `/audio/transcriptions`HighJun 6, 2024- LangChain (Web Research Retriever): SSRFHighJun 6, 2024
- Jupyter Server (Windows): Unauthenticated attackers can leak the NTLM hash of the hostHighJun 6, 2024
- MLflow (model flavors): Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)HighJun 4, 2024
- MLflow (recipes / pyfunc): RCE via a maliciously crafted MLprojectHighJun 4, 2024
- Qdrant (snapshot recovery): Arbitrary file read and write during snapshot recoveryCriticalJun 3, 2024
- Ollama: Path traversal in the digest fieldHighMay 31, 2024
- joblib (`NumpyArrayWrapper.read_array`): Deserialization vulnerability in joblib 1.4.2HighMay 17, 2024
llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CriticalMay 14, 2024
llama.cpp (`gguf_init_from_file`): Use of uninitialized heap variableHighApr 26, 2024- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelMediumApr 19, 2024
- PyTorch (mobile interpreter): Use-after-free in `torch/csrc/jit/mobile/interpreter.cpp`HighApr 17, 2024
- BentoML: Insecure deserializationCriticalApr 16, 2024
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCriticalApr 16, 2024
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCriticalApr 16, 2024
- MLflow (`_create_model_version`): Path traversal in model-version creationHighApr 16, 2024
- Gradio (`/component_server`): Arbitrary method invocation on componentsHighApr 16, 2024
- Qdrant (snapshot upload): Path traversal + arbitrary file upload via `/collections/{c}/snapshots/upload`CriticalApr 10, 2024
- Gradio: Local file inclusion via improper input validationHighApr 10, 2024
- Ollama: DNS rebinding grants a remote page full API accessMediumApr 8, 2024
- JupyterHub: Malicious subdomain tricks a userHighMar 27, 2024
- Gradio: SSRF in the `/proxy` routeMediumMar 27, 2024
- Jupyter Server Proxy: Authentication weakness in proxied-process accessCriticalMar 20, 2024
- LangChain: Directory traversal via the template path parameterHighMar 4, 2024
- langchain-experimental: Second bypass of CVE-2023-44467CriticalFeb 26, 2024
llama.cpp / GGUF library: Heap buffer overflow in GGUF `infoHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `GGUF_TYPE_ARRAY`/`GGUF_TYPE_STRING` parsingHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `header.n_tensors` handlingHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `gguf_fread_str`HighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `header.n_kv`HighFeb 26, 2024- ONNX: Directory traversal in `external_data` — bypass of the 1.13 fixHighFeb 23, 2024
ClearML web server: XSSCriticalFeb 6, 2024
ClearML fileserver: No authentication — arbitrary read/write/delete of all stored artifactsCriticalFeb 6, 2024
ClearML API server: CSRF against the API serverCriticalFeb 6, 2024
ClearML client SDK: Deserialization of untrusted dataHighFeb 6, 2024
ClearML client SDK: Path traversal — a malicious dataset writes arbitrary files on the consumerHighFeb 6, 2024- Gradio: Remotely triggerable local file include via a JSON value in an API requestCriticalFeb 5, 2024
ClearML: Passwords stored in plaintext in MongoDBMediumFeb 5, 2024- jupyter-lsp: Unauthenticated file read/write through the LSP extensionHighJan 18, 2024
- Pure Storage FlashArray Purity API endpoint: MULTI-TENANT ISOLATION: a specific call to a FlashArray endpoint escalatesCritical2024
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryHigh2024
2021
2020
- TensorFlow (SavedModel protobuf): Mutating a SavedModel protobuf crashes or corrupts the serving processCriticalSep 25, 2020
- TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer modelsMediumSep 25, 2020
- scikit-learn / joblib: `joblib.load()` executes commands from an untrusted file via `__reduce__`CriticalMay 15, 2020