Database/AI/ML frameworks & serving
AI/ML framework and model serving vulnerabilities
CVEs and advisories in inference servers, training frameworks, and model formats: Triton, vLLM, TorchServe, Ray, MLflow, Jupyter, and the rest of the tenant-facing AI layer. On shared GPU infrastructure these are the bugs a tenant can reach first.
458 entries120 critical6 known exploitedFilter and search this layer
2026266
- Mooncake transfer engine: zero-length handshake frame crashes the hosting inference processHighOct 3, 2026
- GitLab AI Gateway: crafted Duo flow config escapes the prompt template sandbox into command executionCriticalOct 2, 2026
- Langchain-Chatchat: arbitrary file write outside the upload and knowledge-base directoriesUnscoredOct 1, 2026
- vLLM: crafted request to the Gemma4 unified parser crashes the inference serverMediumSep 30, 2026
SGLang: duplicate bootstrap_room values crash or hang the disaggregated schedulerHighSep 29, 2026- LightLLM: unbounded key-value writes on the NCCL control channel exhaust worker memoryHighSep 29, 2026
- Ollama: agent-mode Bash approval does not parse shell syntax, so appended commands run unapprovedHighSep 29, 2026
- JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated originHighSep 29, 2026
- NVIDIA DeepStream: crafted tensor dimensions in a YAML config trigger an integer overflowHighSep 29, 2026
- JupyterLab: language-pack Plural-Forms header reaches new Function, executing code in the session originMediumSep 29, 2026
- JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRFMediumSep 29, 2026
- Unsloth Zoo: model config.json injects Python that runs via exec() when a model is loadedHighSep 28, 2026
- Langflow: authenticated user reaches eval() through component input options and runs code on the hostLowSep 28, 2026
- Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socketCriticalSep 27, 2026
- vLLM: --revision pin ignored for some FunAudioChat and Tarsier2 processor, tokenizer and config loadsHighSep 26, 2026
- vLLM: out-of-vocabulary stop_token_ids kill EngineCore and take the model server down until restartHighSep 26, 2026
- vLLM: remote media is fully materialized before size and per-prompt limits are enforcedHighSep 26, 2026
- vLLM: overlong token_ids on the disaggregated serving endpoint crash the workerHighSep 26, 2026
- vLLM: out-of-range stop_token_ids trigger a CUDA device assertion and wedge EngineCoreHighSep 26, 2026
- vLLM: unbounded cache_salt stalls the EngineCore scheduler thread, denying service to all requestsMediumSep 26, 2026
- vLLM: audio clip size limit not enforced, letting unauthenticated clients exhaust node memory and CPUMediumSep 26, 2026
- vLLM: video decoder limit bypass via sampler subclass shadowing exhausts unaccounted GPU memoryMediumSep 26, 2026
- LangChain4j agentic: unsafe Jackson default typing in AgenticScope deserialization allows arbitrary class instantiationLowSep 25, 2026
- Decepticon: unfiltered ChatML special tokens in crawl results give a target page control of the agentCriticalSep 24, 2026
- NVIDIA NeMo: TabularTokenizer unpickles an attacker-supplied .pkl file, giving code executionHighSep 22, 2026
- NVIDIA NeMo Speech: malicious input data leads to remote code executionHighSep 22, 2026
- NVIDIA NeMo Speech: RCE and privilege escalation in the speech data explorerHighSep 22, 2026
- NVIDIA NeMo Speech: code injection from malicious input, no user interaction neededHighSep 22, 2026
- NVIDIA NeMo: a crafted model_config.yaml injects unsafe parameters into dataset loadingHighSep 22, 2026
- vLLM: incomplete NIXL kv_transfer_params kills the decode engine with an uncaught KeyErrorHighSep 21, 2026
- vLLM: multi-prompt completion request trips a NIXL prefix-caching assertion and kills the decode workerHighSep 21, 2026
- vLLM: attacker-chosen P2P offload peers exhaust ZeroMQ contexts and crash EngineCoreHighSep 21, 2026
- vLLM: unvalidated tp_size in kv_transfer_params drives the decode worker into OOM-killHighSep 21, 2026
- vLLM: Mooncake transfer-ID collision leaks GPU KV cache blocks until restartHighSep 21, 2026
- vLLM: rejected prefill requests leak Mooncake transfer placeholders, stalling valid requestsMediumSep 21, 2026
- vLLM: unvalidated bad_words token indices corrupt logits of other in-flight requestsLowSep 19, 2026
- vLLM: negative token IDs in embeddings requests poison the CUDA context and wedge the engineHighSep 18, 2026
- vLLM: allowed_token_ids validated against tokenizer length, corrupting shared GPU logit-bias stateMediumSep 18, 2026
- vLLM: unbounded prompt token ids write out of bounds in the penalty bincount Triton kernelMediumSep 18, 2026
SGLang: unauthenticated PUT /route poisons the KV transfer routing table in disaggregated modeHighSep 17, 2026- vLLM: rejected requests leak decode-worker metadata until the worker exhausts memoryHighSep 17, 2026
- MKP Kubernetes MCP server: unauthenticated log request exhausts server memoryHighSep 17, 2026
- Jupyter Server: Referer header is logged unscrubbed, leaking auth tokens into server logsHighSep 17, 2026
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesHighSep 16, 2026
- vLLM: unvalidated MoRIIO ack fields let a remote client exhaust resources on a serving nodeMediumSep 16, 2026
- vLLM: audio input in chat completions skips the decode-duration limit, letting a small clip OOM the workerMediumSep 16, 2026
- vLLM: request-selected video decoder backend allocates GPU memory outside the KV-cache budgetMediumSep 16, 2026
- gitlab-mcp: unauthenticated SSE transport plus arbitrary file read leaks the GitLab tokenCriticalSep 15, 2026
- GitLab MCP server: attacker-supplied API URL header exfiltrates the configured GitLab tokenCriticalSep 15, 2026
- GitLab MCP server: DNS rebinding reaches the Streamable HTTP endpoint from a web pageCriticalSep 15, 2026
- vLLM: attacker-supplied chat_template burns server resources on the GPU nodeLowSep 15, 2026
Langflow OSS: submitted components run arbitrary Python as root on the serverCriticalSep 14, 2026- LangBot: debug WebSocket on 0.0.0.0:5401 accepts plugin registration with no key setHighSep 14, 2026
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsHighSep 14, 2026
- tract: unchecked size multiplication when reading an NNEF tensor gives a heap over-read on model loadMediumSep 14, 2026
- tract: ONNX external_data path is not sanitised, so loading a model reads arbitrary local filesMediumSep 14, 2026
- vLLM: malformed tiktoken vocab file crashes the tokenizer backend, denying service on the GPU nodeLowSep 14, 2026
- vLLM: remote processor code executes even when trust_remote_code is falseHighSep 12, 2026
- vLLM: forged FLAC sample rate bypasses duration limit and crashes the API serverHighSep 12, 2026
- vLLM: audio extracted from video input ignores decode size and duration limitsMediumSep 12, 2026
SGLang: unauthenticated pickle deserialization on /update_weights_from_tensor gives code executionUnscoredSep 11, 2026- MLflow: a crafted model artifact runs arbitrary code when the model is loadedHighSep 8, 2026
- NVIDIA Triton Inference Server: unauthenticated request triggers excessive iteration and hangs the serverHighSep 8, 2026
- NVIDIA Triton Inference Server: missing authorization lets an unauthenticated caller reach protected operationsHighSep 8, 2026
- n8n OpenAI Chat Model node: model-search path ignores credential domain limits and leaks the API keyHighSep 8, 2026
- Eclipse Che dashboard backend (POST /dashboard/api/data/resolver): The dashboard backend passes a user-supplied URLMediumSep 8, 2026
llama.cpp RPC server: crafted tensor dimensions hit a reachable assertion and abort the processMediumSep 7, 2026- OpenShift AI dashboard: unauthorized Secret read exposes the cluster NGC API key and NIM pull secretMediumSep 7, 2026
Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileLowSep 7, 2026- Bifrost LLM gateway: unauthenticated plugin API loads a remote shared object, giving RCE on dynamic buildsHighSep 6, 2026
- Axolotl: multipack patch loads Hugging Face base models with trust_remote_code=True, giving RCE on the training nodeHighSep 5, 2026
- Hugging Face tokenizers: crafted tokenizer.json aborts the process while loading a BPE modelHighSep 4, 2026
- Ollama: model pull follows cross-host redirects, giving SSRF to internal and metadata endpointsHighSep 3, 2026
- NVIDIA Megatron Bridge: deserialization of untrusted checkpoints or configs gives code executionHighSep 1, 2026
llama.cpp: uncontrolled recursion in JSON-schema-to-grammar conversion crashes the serverHighSep 1, 2026
llama.cpp: a crafted GGUF file trips a reachable assertion and aborts the process loading itUnscoredSep 1, 2026
llama.cpp server: negative top_n on /rerank drives an unbounded allocation and denial of serviceUnscoredSep 1, 2026- Hugging Face Transformers: load_custom_generate writes remote code to disk before the trust checkUnscoredSep 1, 2026
- MCPHub: any authenticated user can register an MCP server and run arbitrary commands as the service userCriticalAug 31, 2026
- iFlytek astron-agent: copyFlow lacks an ownership check, letting any tenant read or overwrite workflowsHighAug 29, 2026
Kubeflow Pipelines frontend: unauthenticated SSRF proxy reaches cloud metadata and cluster-internal APIsCriticalAug 28, 2026- Gitingest: prefix-only host validation lets crafted URLs leak GitHub tokens to attacker hostsHighAug 28, 2026
- vLLM: unbounded media download from user-supplied URLs exhausts inference server memoryHighAug 28, 2026
- GitLab AI Gateway: crafted model metadata redirects model requests and discloses Vertex or Bedrock credentialsHighAug 27, 2026
- GitLab AI Gateway: crafted inline flow config overrides the HTTP Host header and leaks Vertex credentialsHighAug 27, 2026
- Spring AI: predictable ONNX model cache path lets a local user plant a substitute model fileHighAug 27, 2026
- NVIDIA OpenShell: incomplete input denylist in the sandbox provisioning API allows code executionCriticalAug 25, 2026
- NVIDIA OpenShell: sandbox escape lets confined code run outside the sandboxCriticalAug 25, 2026
- NVIDIA OpenShell: a malicious gateway can inject OS commands into the connecting clientHighAug 25, 2026
- Vocos: model config can name any importable class, so from_pretrained runs the repo owner's codeHighAug 25, 2026
- NVIDIA OpenShell Sandbox: path traversal bypasses L7 REST network policy, exposing blocked endpointsHighAug 25, 2026
- mcp-shell: allowlist validates only the first token, so /bin/bash -c runs any commandHighAug 25, 2026
- mcp-shell: allowed git binary runs arbitrary commands via a `!` alias, bypassing secure modeHighAug 25, 2026
- NVIDIA NemoClaw: installation process executes untrusted codeHighAug 25, 2026
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyHighAug 25, 2026
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowHighAug 25, 2026
- NVIDIA NemoClaw: inference service comes up without authentication, reachable from the adjacent networkHighAug 25, 2026
- NVIDIA NemoClaw: OS command injection in the status and logs plugin commandsHighAug 25, 2026
- NVIDIA NemoClaw: OS command injection in the NIM management componentHighAug 25, 2026
- NVIDIA NemoClaw: OS command injection in the Telegram bridge componentHighAug 25, 2026
- NVIDIA NemoClaw: OS command injection through the command-line interfaceHighAug 25, 2026
- NVIDIA NemoClaw for Linux: installer downloads code without an integrity checkHighAug 25, 2026
- NVIDIA NemoClaw: code injection in the migration command gives a local user execution as the tool's privilegesHighAug 25, 2026
- vLLM: DeepStream backend misclassification skips pixel limits and lets unauthenticated video exhaust GPU decodeMediumAug 25, 2026
- NVIDIA OpenShell: sandbox exec handler is vulnerable to OS command injection, breaking the sandbox boundaryMediumAug 25, 2026
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingMediumAug 25, 2026
- NVIDIA NemoClaw: sensitive information visible in process invocation leads to information disclosureMediumAug 25, 2026
- NVIDIA OpenShell for Linux: improper output encoding in the inference proxy leaks data and allows tamperingMediumAug 25, 2026
- Xinference: model launch API executes attacker-supplied Python because trust_remote_code is always onHighAug 24, 2026
llama.cpp ggml RPC server: null pointer dereference in graph_compute kills the GPU workerMediumAug 24, 2026- BentoML: SSRF filter misses 100.64.0.0/10, so serving pods fetch from internal CGNAT hostsMediumAug 24, 2026
llama.cpp ggml RPC server: unvalidated tensor op and op_params in deserialize_tensorMediumAug 23, 2026- Xinference: unauthenticated chat request reaches eval() in the Llama3 tool-call parserCriticalAug 21, 2026
- Headroom: client-supplied x-headroom-user-id header is trusted as identity, exposing other users' memoryCriticalAug 21, 2026
llama.cpp: use-after-free in the RPC server GRAPH_RECOMPUTE handler gives unauthenticated RCECriticalAug 21, 2026- Headroom LLM proxy: client-chosen upstream base URL enables SSRF and leaks the Authorization headerHighAug 21, 2026
- ONNX: symlink-following external-data write lets a local attacker append to victim-writable filesMediumAug 21, 2026
- Darknet: integer overflow in convolutional layer sizing yields a heap overflow from a crafted .cfgHighAug 20, 2026
- timm: untrusted checkpoint deserialization executes arbitrary code in the loading processHighAug 20, 2026
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFHighAug 20, 2026
- LMDeploy: unauthenticated p2p endpoints let a remote peer deliver a pickle payload for engine RCECriticalAug 19, 2026
- mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference serverLowAug 18, 2026
- MLflow: unauthenticated webhook test follows redirects, turning the tracking server into an SSRF proxyCriticalAug 17, 2026
- MLflow: model version creation reads another user's run artifacts without READ permissionHighAug 17, 2026
- Hugging Face Transformers: checkpoint index shard names traverse out of the model directoryMediumAug 17, 2026
- MLflow: missing permission check on runs/log-inputs lets any user forge another run's lineageMediumAug 17, 2026
- vLLM: MiMo-V2-Omni processor bypasses media allowlists, enabling SSRF and local file readsMediumAug 17, 2026
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryMediumAug 17, 2026
- Flowise: custom-function sandbox escape via puppeteer.launch gives command execution as the Flowise userCriticalAug 13, 2026
- JupyterLab: missing await skips extension allowlist check for direct PyPIExtensionManager callersHighAug 13, 2026
- vLLM: unbounded prompt array in /v1/completions lets one request exhaust the engineMediumAug 13, 2026
- vLLM: race in the prompt_embeds sparse-tensor guard reopens the CVE-2025-62164 crash pathMediumAug 13, 2026
- JupyterLab: authenticated users bypass administrator plugin lock rules via /lab/api/pluginsMediumAug 13, 2026
- vLLM: malformed JSON to the OpenAI-compatible endpoints returns server paths and versionsMediumAug 13, 2026
- vLLM: attacker-supplied structured-output regex pins a CPU core and stalls the engine pathMediumAug 13, 2026
- vLLM: integer overflow in the activation CUDA kernel leaks another batched request's outputMediumAug 13, 2026
- JupyterLab: crafted SVG in the image viewer yields same-origin XSS and code execution on the serverHighAug 12, 2026
- Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalationMediumAug 11, 2026
- Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalationMediumAug 11, 2026
- OpenShift AI MaaS API: any in-cluster pod forges identity headers to impersonate tenantsCriticalAug 10, 2026
- OpenShift AI training-operator: namespace edit/admin users escalate to host filesystem access via crafted training jobsHighAug 10, 2026
- OpenShift AI Data Science Pipelines Operator: predictable PRNG generates MariaDB and MinIO credentialsHighAug 10, 2026
- Hugging Face Accelerate: unsanitized shard paths in a checkpoint index give arbitrary file read and hangsMediumAug 10, 2026
- Keras: unvalidated dataset sizes in .keras loading let a poisoned model exhaust node memoryMediumAug 10, 2026
- Feast operator: tenant-supplied feature repo code runs with elevated privileges, reaching cluster adminMediumAug 10, 2026
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageMediumAug 7, 2026
llama.cpp llama-server: use-after-free on the vocab pointer during idle sleep gives unauthenticated RCECriticalAug 6, 2026
llama.cpp llama-server: crafted sampler parameter triggers out-of-bounds read and unauthenticated crashHighAug 6, 2026
llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`HighAug 6, 2026
llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsHighAug 6, 2026
llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplicationHighAug 6, 2026
llama.cpp: oversized seq_id in a saved slot file leaks heap memory past the cells arrayMediumAug 6, 2026- Hugging Face peft: CorDA and LoRA-GA load cache files with unsafe torch.load, giving code executionHighAug 5, 2026
- Milvus: Unauthenticated DoS terminating service componentsHighAug 5, 2026
- MLflow AI Gateway: unvalidated api_base in gateway secrets turns the proxy endpoint into an authenticated SSRFHighAug 5, 2026
- Flowise: SQLite Record Manager config override gives an authenticated user root code execution in the containerCriticalAug 4, 2026
- LangGraph.js MongoDB checkpointer: NoSQL injection in thread ids leaks checkpoints across tenantsMediumAug 4, 2026
- Hugging Face Transformers: path traversal in save_pretrained() writes files outside the save directoryHighAug 2, 2026
- Keras: malicious .keras/.h5 weights file reads arbitrary local files via HDF5 ExternalLinksMediumAug 2, 2026
- JupyterLab: stored XSS from javascript: URLs in extension metadata shown by Extension ManagerMediumAug 1, 2026
- sentence-transformers: local model directory executes Python despite trust_remote_code=FalseCriticalJul 31, 2026
SGLang (`/load_lora_adapter_from_tensors`): Unauthenticated RCE bypassing `SafeUnpickler`'s incomplete denylistCriticalJul 30, 2026
SGLang (`/server_info`): Endpoint returns API keys and SSL keyfile pathsHighJul 30, 2026
SGLang (weight exfiltration): Two endpoints allow a remote attacker to pull model weights when no API key is setHighJul 30, 2026- OpenShift AI dashboard: incorrect network binding lets an in-cluster actor impersonate any user with an arbitrary tokenHighJul 23, 2026
- torchvision (GIF decoder): Out-of-bounds heap read in `read_from_tensor` GIF decodeHighJul 23, 2026
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`MediumJul 23, 2026
Kubeflow Community Distribution: Insecure default in the platform installHighJul 21, 2026- Ollama (GGUF metadata parser): Uncontrolled memory allocationHighJul 21, 2026
- Keras (`TorchModuleWrapper`): Unsafe deserialization of attacker-controlled PyTorch pickle inside a Keras modelHighJul 19, 2026
SGLang (expert-parallel backup ZMQ PULL): Unauthenticated, unvalidated deserialization on a routable interfaceCriticalJul 16, 2026- Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpointHighJul 16, 2026
LiteLLM (MCP server creation): RCE via MCP server registrationCriticalJul 15, 2026- PyTorch Lightning (`_load_state`): RCE by importing and executing classes named in the checkpointHighJul 15, 2026
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityLowJul 13, 2026
- OpenShift AI guardrails-detectors: unauthenticated blind SSRF and file read via crafted XSDCriticalJul 10, 2026
LiteLLM Proxy: forged Authorization header reaches MCP tooling without a valid API keyHighJul 8, 2026- TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIsMediumJul 8, 2026
LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLsHighJul 7, 2026- Keras (Lambda layer): Arbitrary code execution via Lambda-layer deserialization in 3.14.0CriticalJul 3, 2026
Weaviate: RBAC role assignment does not verify the assigner holds the granted permissionsHighJul 2, 2026- Ray (WebDataset reader): Unsafe deserializationHighJul 1, 2026
- Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file readMediumJul 1, 2026
- Ollama (quantization engine): Unauthenticated remote information disclosure — reads and exfiltrates model dataHighJun 26, 2026
LiteLLM proxy: Host-header parsing flaw in the proxyCriticalJun 22, 2026- Jupyter Server: notebook HTML rendered without CSP sandbox gives stored XSS and kernel RCECriticalJun 22, 2026
- vLLM: ASGI request handling lets callers bypass API-key authentication on the OpenAI endpointsCriticalJun 22, 2026
- vLLM (activation function loading): Assert-based security check bypass, unauthenticatedHighJun 22, 2026
- vLLM (revision pinning): Revision pinning does not apply to all model artifactsMediumJun 22, 2026
- vLLM - sampling parameter validation: Temperature validation uses strict comparison operators, so boundary values slipMediumJun 22, 2026
- vLLM (sparse tensor validation): Missing sparse-tensor invariant checks in multimodal embeddingsHighJun 20, 2026
- picklescan: `scan_pytorch` bypass via forged magic numbersHighJun 17, 2026
stable-diffusion.cpp: Memory-safety flaw in model loadingHighJun 16, 2026
ChromaDB (SimpleRBAC): Authorization provider evaluates permissions incorrectlyHighJun 12, 2026
ChromaDB (V1 endpoints): Tenant/database passed as `None` to the authz layerHighJun 12, 2026
ChromaDB: Authenticated code injectionHighJun 12, 2026
ChromaDB (Rust): Missing authorization validationHighJun 12, 2026- Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`HighJun 11, 2026
- Transformers: LightGlue config re-enables trust_remote_code from the model repo, executing repo code at loadCriticalJun 3, 2026
- OpenMed: unauthenticated model_name routes to a trust_remote_code loader and executes attacker codeCriticalJun 2, 2026
- vLLM (hardcoded `trust_remote_code=True`): Two model implementation files force remote code execution regardlessHighMay 28, 2026
- BentoML (`bentofile.yaml`): Malicious build manifestHighMay 27, 2026
- Starlette: malformed Host header makes request.url.path diverge from the routed pathMediumMay 26, 2026
- HuggingFace transformers: Critical RCE in all versions before 5.3.0HighMay 24, 2026
- Docker Model Runner (vllm-metal backend): `trust_remote_code=True` set unconditionally, no sandboxHighMay 22, 2026
LiteLLM (key generation): internal_user can mint keys with routes their role forbidsHighMay 21, 2026
LiteLLM (`/user/update`): User can self-elevate `user_role`HighMay 21, 2026
ChromaDB: Pre-authentication code injectionCriticalMay 18, 2026
SGLang (scheduler ROUTER socket): ROUTER socket binds `0.0.0.0` by default and `pickle.loads()` incoming messagesCriticalMay 18, 2026
SGLang (custom logit processor): `dill.loads` on user objects when `--enable-custom-logit-processor` is setCriticalMay 18, 2026
SGLang (multimodal runtime): Unauthenticated path traversalCriticalMay 18, 2026- PyTorch Lightning: Reintroduced unsafe deserialization in 2.6.2CriticalMay 14, 2026
- JupyterLab: extension allow-list not enforced, letting a notebook user install arbitrary PyPI packagesHighMay 13, 2026
- JupyterLab: saved HTML cell output can run arbitrary JupyterLab commands on one user clickHighMay 13, 2026
Kubeflow (ART component): RCE in the robustness evaluation functionCriticalMay 12, 2026
Kubeflow (Adversarial Robustness Toolbox component): Insecure deserialization in the Kubeflow model-loading componentCriticalMay 12, 2026- MLflow: unauthenticated arbitrary file read via prompt-tagged model version source pathHighMay 11, 2026
LiteLLM proxy: SQL injection in a database query pathCriticalMay 8, 2026- Ray Data (Arrow extension types): Custom Arrow extension types deserialized unsafelyHighMay 8, 2026
LiteLLM proxy: Two endpoints allow privilege escalation / unauthorized actionHighMay 8, 2026
Dagster: Vulnerability in Dagster Core prior to 1.13.1HighMay 7, 2026- Jupyter Server: Path traversal in the REST APIHighMay 5, 2026
- Jupyter Server (Origin validation): `re.match` used for Origin validationHighMay 5, 2026
- Apache OpenNLP: model archive manifest names any classpath class and runs its static initializerCriticalMay 4, 2026
- Ollama (GGUF model loader): Heap out-of-bounds read from an attacker-supplied GGUF via `/api/create`CriticalMay 4, 2026
SGLang (`/v1/rerank`): RCE via a malicious `tokenizer.chat_template` rendered as Jinja2CriticalApr 20, 2026
LiteLLM (`/guardrails/test_custom_code`): RCE via bytecode rewritingHighApr 10, 2026- HuggingFace transformers (`Trainer._load_rng_state`): Arbitrary code execution when a training run resumesHighApr 7, 2026
LiteLLM (JWT auth): Auth bypass when `enable_jwt_auth` is setCriticalApr 6, 2026
LiteLLM (`/config/update`): Endpoint does not enforce admin authorizationHighApr 6, 2026- BentoML (Dockerfile generation): Injection into generated DockerfileHighApr 6, 2026
- KubeAI (Ollama engine controller): Injection in `ollamaStartupProbeScript()`HighApr 6, 2026
- vLLM: unbounded frame count in video/jpeg base64 data URLs crashes the server with OOMMediumApr 6, 2026
- vLLM: no upper bound on the n parameter lets a single request OOM the API serverMediumApr 6, 2026
- MLflow (jobs API): `/ajax-api/3.0/jobs/*` unauthenticated even with basic-auth enabledCriticalApr 3, 2026
- JupyterHub OAuthenticator: Authenticated user bypasses the intended identity checkHighApr 3, 2026
llama.cpp (RPC `deserialize_tensor`): RPC backend skips all bounds validationCriticalApr 1, 2026- ONNX (`ExternalDataInfo`): Security control bypass in external-data path handlingHighApr 1, 2026
- LangChain: prompt config files are loaded from unvalidated paths, letting a caller read arbitrary host filesHighMar 31, 2026
- vLLM (hardcoded `trust_remote_code`, second instance): Same class, two more model files, through 0.18.0HighMar 27, 2026
- BentoML (`docker.system_packages`): Command injection through the package list fieldHighMar 27, 2026
llama.cpp (`ggml_nbytes`): Integer overflow in the core ggml size calculationHighMar 24, 2026- ONNX: Security-control bypass through 1.20.1HighMar 18, 2026
- Ray Dashboard: Path traversal in the dashboard static-file handler (port 8265)HighMar 17, 2026
SGLang (multimodal ZMQ broker): Unauthenticated RCE via `pickle.loads()` on the ZMQ brokerCriticalMar 12, 2026
SGLang (encoder parallel disaggregation): Unauthenticated RCE via `pickle.loads()` in the disaggregation moduleCriticalMar 12, 2026
SGLang (`replay_request_dump.py`): Insecure `pickle.load()` on a `.pkl` dumpHighMar 12, 2026- vLLM (`load_from_url_async`): Bypass of the CVE-2026-24779 SSRF fixHighMar 9, 2026
- BentoML (`safe_extract_tarfile`): Tar extraction escape despite the "safe" helperHighMar 3, 2026
- Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETEMediumFeb 21, 2026
- MLflow (artifact handler): Directory traversalHighFeb 20, 2026
- Milvus (port 9091): Management port 9091 exposed by default enabling compromiseCriticalFeb 13, 2026
- Keras (HDF5 external links): Arbitrary local file read during model loadHighFeb 11, 2026
- Qdrant (`/logger`): Append to arbitrary files via the logger endpointHighFeb 6, 2026
- vLLM (image error echo): Error path returns sensitive content on invalid image inputCriticalFeb 2, 2026
- PyTorch (`weights_only` unpickler): Bypass of the `weights_only` allowlistHighJan 27, 2026
- vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242HighJan 27, 2026
- vLLM (HF `auto_map`): Loads Hugging Face dynamic modules during model resolutionHighJan 21, 2026
- Dask distributed (+ Jupyter proxy): Exposure when Dask, JupyterLab and jupyter-server-proxy are combinedMediumJan 16, 2026
Adversarial Robustness Toolbox (Kubeflow component, robustness_evaluation_fgsm_pytorch.py): The ART Kubeflow evaluationCritical2026- vLLM (multimodal prompt embeddings, sparse tensor validation): This is the advisory saying the earlier fix did notHigh2026
- MLflow (statsmodels flavor, MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard): SECURITY CONTROL BYPASS LEADING TO RCE: theHigh2026
- BentoML (cloud deployment path, setup.sh generation in deployment.py): The March fix that added shlex.quote to theHigh2026
- BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the buildMedium2026
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedMedium2026
- vLLM (DeepStream video backend, VideoMediaIO backend selection): A performance feature merged past two existingMedium2026
202586
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /create_projectHighAug 17, 2026
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /add_promptsHighAug 17, 2026
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /new_runHighAug 17, 2026
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetHighJul 4, 2026
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetHighJun 25, 2026
- AutoGPT Platform: unbounded container logs fill the host disk and take the service downMediumMay 13, 2026
- Jupyter Server: login `next` parameter allows redirect to an arbitrary external hostMediumMay 5, 2026
- MLflow (`extract_archive_to_dir`): Path traversal in the dbconnect artifact cacheCriticalMar 30, 2026
- MLflow (serving container init): Command injection in `_install_model_dependencies`CriticalMar 30, 2026
- MLflow (pyfunc tar extraction): Arbitrary file write from crafted tar entriesCriticalMar 18, 2026
- Linux i915 GPU kernel driver (execbuffer VMA array): The execbuffer VMA array was not zero-initialised, soHighJan 14, 2026
- Ollama: malformed base64 image data crashes the model runner via null pointer dereferenceHighJan 12, 2026
- MLflow (REST API): DNS rebinding — no Origin header validationHighJan 12, 2026
- LibreChat: agent Actions have no destination restrictions by default, reaching internal services via SSRFHighJan 7, 2026
- Ollama (API auth): Critical authentication bypass on API endpoints through v0.12.3CriticalDec 18, 2025
- nbconvert: Template-driven conversion executes attacker contentHighDec 17, 2025
Weaviate: Crafted entry name with an absolute pathHighDec 12, 2025
Portkey AI Gateway: Gateway resolves the destination baseURL from attacker-controlled precedenceCriticalDec 1, 2025- vLLM (`Nemotron_Nano_VL_Config`): RCE via a config class evaluated at model loadHighDec 1, 2025
- Keras (`utils.get_file`): Path traversal in tar extraction in 3.11.3 (incomplete fix)HighNov 28, 2025
- vLLM (multimodal embeddings): Memory corruptionHighNov 21, 2025
- Milvus: Unauthenticated attacker exploits the server directlyCriticalNov 10, 2025
- Keras (`utils.get_file`, tar extract): Path traversal on tar extractionHighOct 30, 2025
- MLflow (auth): Weak password requirementsCriticalOct 29, 2025
- MLflow (model creation): Directory traversal on model creationCriticalOct 29, 2025
- Keras: Deserialization of untrusted data in 3.11.0–3.11.2CriticalOct 17, 2025
- vLLM (API key comparison): Timing attack recovers the API keyHighOct 7, 2025
- vLLM (`MediaConnector` SSRF): SSRF via `load_from_url` in multimodal input handlingHighOct 7, 2025
- Red Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromiseCriticalSep 30, 2025
KServe ModelMesh: Group-writable `/etc/passwd` in the container imageMediumSep 30, 2025
llama-index-core: Predictable hardcoded cache directoryHighSep 27, 2025- PyTorch (`torch.linalg.lu`): DoS on slice operationHighSep 25, 2025
- PyTorch (KV/conv path buffer overflow): Buffer overflow when a model combines Conv2d + hardshrink + viewHighSep 25, 2025
- Keras (HDF5 path): Code execution from crafted `.h5`/`.hdf5` model despite safe modeHighSep 19, 2025
- Keras: Code execution from crafted `.keras` archive despite safe modeHighSep 19, 2025
- NVIDIA Triton Inference Server (Python backend): Attacker-controlled input in the Python backendCriticalSep 17, 2025
- picklescan: Improper input validation lets a crafted pickle evade scanningHighSep 17, 2025
- mcp-kubernetes-server: chained kubectl commands bypass the read-only --disable-write/--disable-delete guardsMediumSep 15, 2025
- Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted inputMediumSep 14, 2025
SGLang (`/update_weights_from_tensor`): Unsafe deserialization of the `serialized_named_tensors` argumentHighSep 9, 2025- vLLM (HTTP GET): Single HTTP GET crashes the serverHighAug 21, 2025
- Keras: Safe-mode bypass in Keras 3.0.0–3.10.0HighAug 11, 2025
- skops (`Card.get_model`): Model card loading has no trusted-types checkHighAug 8, 2025
- NVIDIA Triton: Stack buffer overflowCriticalAug 6, 2025
- NVIDIA Triton: Stack overflow via crafted requestCriticalAug 6, 2025
- NVIDIA Triton (HTTP server): Attacker can start a reverse shell from the HTTP serverCriticalAug 6, 2025
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendHighAug 6, 2025
- NVIDIA Triton (Python backend shared memory): Out-of-bounds write in the Python backendHighAug 6, 2025
- NVIDIA Triton (Python backend): Information disclosure from the Python backendHighAug 6, 2025
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`MediumAug 6, 2025
- BentoML (file upload): SSRF in the file-upload pathCriticalJul 29, 2025
- skops (scikit-learn model sharing): Inconsistency in the `Operator` handling lets an untrusted model bypass the safeHighJul 26, 2025
- skops: Method-handling inconsistencyHighJul 26, 2025
- ONNX (`save_external_data`): Path traversalHighJul 22, 2025
Dagster (gRPC `get_notebook_data`): Local file inclusion — read arbitrary filesMediumJul 22, 2025
llama.cpp (`gguf_init_from_file_impl`): Integer overflow in GGUF initHighJul 10, 2025
llama.cpp (vocab): Attacker-supplied GGUF vocabulary triggers memory corruptionHighJun 17, 2025
LlamaIndex (vector store integrations): SQL injection across multiple vector store integrationsCriticalJun 5, 2025- Jupyter Core (Windows): Config read from a shared writable pathHighJun 3, 2025
- vLLM (`/v1/completions` guided decoding): Invalid `json_schema` kills the serverMediumMay 30, 2025
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsLowMay 29, 2025
LlamaIndex CLI: OS command injection via the `--files` argumentHighMay 28, 2025- vLLM (`PyNcclPipe` KV transfer): RCE via the KV cache transfer integrationCriticalMay 20, 2025
- vLLM (multi-node ZeroMQ): Secondary vLLM host trusts unauthenticated ZeroMQ messagesHighMay 6, 2025
- vLLM (Mooncake ZMQ/TCP): Unsafe deserialization exposed on all interfacesCriticalApr 30, 2025
- vLLM (ZeroMQ): DoS and data exposure over ZeroMQHighApr 30, 2025
- PyTorch (`torch.load`): RCE via unsafe deserialization even with `weights_only=True`CriticalApr 18, 2025
- BentoML: Insecure deserialization RCE prior to 1.4.8CriticalApr 9, 2025
- BentoML: RCE via insecure deserializationCriticalApr 4, 2025
- Ollama (GGUF import): Crafted GGUF causes DoS on model createHighMar 20, 2025
- vLLM (Mooncake): Unsafe deserialization over ZMQ/TCP bound to all interfacesCriticalMar 19, 2025
- Keras (`Model.load_model`): Arbitrary code execution from a crafted `.keras` archive even with `safe_mode=True`CriticalMar 11, 2025
- picklescan (model scanner): Scanner fails to detect malicious pickles when ZIP flag bits are flippedCriticalMar 10, 2025
- picklescan: ZIP manipulation crashes the scanner (scan bypass by DoS)MediumMar 10, 2025
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesLowFeb 7, 2025
- vLLM (weight loading): `hf_model_weights_iterator` uses `torch.load` without `weights_only`HighJan 27, 2025
- Ray (dashboard job submission API, browser-origin guard): Ray's only defense against browser-driven job submission wasCritical2025
- vLLM OpenAI-compatible server (qwen3_coder tool-call parser): Code execution inside the serving process, which on a GPUHigh2025
- Pure Storage FlashArray authentication input validation: Malformed input during authentication takes the FlashArrayHigh2025
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYHigh2025
- BentoML 1.3.9 (bundled Gradio app, /login endpoint): The /login endpoint of the integrated Gradio app processes eachHigh2025
llama.cpp (GGUF vocabulary parsing, llama_vocab::impl::print_info): MALICIOUS MODEL FILE CRASHES THE SERVER: the GGUFMedium2025- vLLM OpenAI-compatible server (chat_template / chat_template_kwargs): NOISY-NEIGHBOUR DENIAL OF SERVICE: one tenantMedium2025
- Ray (GCS Redis credential handling / logging): When the Redis password is passed on the Ray command line it getsMedium2025
- BentoML 1.3.9 (open redirect in the serving UI): A crafted URL against the BentoML server bounces the visitor to anMedium2025
- Pure Storage FlashArray key rotation logging (Rapid Data Locking): The Key Encryption Key is written to logs duringMedium2025
202324
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sLowSep 6, 2025
Dagster (webserver): Directory traversalHighJul 7, 2025- Gradio: Command injectionHighDec 14, 2023
Kubeflow: SSRFMediumDec 14, 2023- Ray (job submission API): Unauthenticated RCE — the Jobs API accepts arbitrary code by designCriticalNov 28, 2023
- Ray (`/log_proxy`): SSRF from the dashboardCriticalNov 28, 2023
- TorchServe (model/workflow API): Information disclosure of files on the serving hostMediumNov 21, 2023
- MLflow: Arbitrary account creation bypassing authenticationCriticalNov 16, 2023
- MLflow: Overwrite any file on the MLflow host without authenticationCriticalNov 16, 2023
- Ray (dashboard `cpu_profile`): Command injectionCriticalNov 16, 2023
- Ray (log API): LFI — read any file on the head node, unauthenticatedHighNov 16, 2023
- LangChain (recursive URL loader): SSRF — crawling proceeds to internal hostsHighOct 19, 2023
- langchain-experimental (PALChain): Bypass of the CVE-2023-36258 fixCriticalOct 9, 2023
- TorchServe: Unauthenticated SSRFCriticalSep 28, 2023
- LangChain (`load_prompt`): Arbitrary code execution from a JSON prompt fileCriticalAug 22, 2023
- MLflow: Absolute path traversal prior to 2.5.0CriticalJul 19, 2023
- LangChain (PALChain): Arbitrary code execution via `os.system`/`exec` in generated codeCriticalJul 3, 2023
- Gradio: Lack of path filteringHighJun 8, 2023
- MLflow: Path traversal prior to 2.3.1CriticalMay 17, 2023
- LangChain (`LLMMathChain`): Prompt injectionCriticalApr 5, 2023
- MLflow (tracking server): Path traversal (`\..\filename`)CriticalMar 24, 2023
- MLflow (mlflow server / mlflow ui, Model Registry): REMOTE FILE ACCESS on the host running the tracking and registryCritical2023
- Ray (dashboard /static/ file handler): Path traversal under the dashboard's /static/ route lets an unauthenticatedCritical2023
- Pure Storage FlashArray VASA provider: A vSphere or ESXi administrator with VASA access to a FlashArray escalates toHigh2023
20224
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsMediumMay 1, 2025
- ONNX: Directory traversal via `external_data` field in the tensor protoHighJan 26, 2023
- PyTorch (`torch.jit.annotations.parse_type_line`): Arbitrary code execution via unsafe `eval` in TorchScript typeCriticalNov 26, 2022
- joblib: Arbitrary code execution via `eval` on the `pre_dispatch` flag in `Parallel()`HighSep 26, 2022
202473
- vLLM (MessageQueue / ZMQ): `pickle.loads` on socket dataCriticalMar 20, 2025
- vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypointsCriticalMar 20, 2025
- BentoML (runner server): Deserialization RCE on the internal runner serverCriticalMar 20, 2025
- ONNX (`download_model`): Arbitrary file overwriteCriticalMar 20, 2025
LiteLLM: Unauthenticated DoS via `ast.literal_eval` on user inputHighMar 20, 2025- OpenLLM: Local file inclusion via the web applicationMediumMar 20, 2025
- Weights & Biases OpenUI: Unauthenticated endpoints allow file upload and downloadMediumFeb 10, 2025
- MLflow (`spark_udf` dir perms): Excessive directory permissionsHighNov 25, 2024
Kubeflow (Pipelines UI): Stored XSS in the pipeline viewMediumNov 18, 2024- Ollama (GGUF parser): Malformed 4-byte GGUF file crashes the server (two HTTP requests)HighOct 31, 2024
- Ollama: File-existence disclosure via `api/create`HighOct 31, 2024
- Ollama: Path traversal in `api/push` discloses server filesystem layoutHighOct 31, 2024
- PyTorch (`torch.distributed` RemoteModule / RPC): Deserialization RCE across the distributed RPC channelCriticalOct 29, 2024
- Gradio: SSRF from the file-upload/proxy pathCriticalOct 10, 2024
- Gradio: CORS origin validation bypassHighOct 10, 2024
LocalAI: RCE — the backend accepts inputs beyond the config pathHighSep 27, 2024- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CriticalSep 19, 2024
- LangChain (`FAISS.deserialize_from_bytes`): Pickle deserialization of an untrusted vector indexHighSep 17, 2024
- Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directoryHighAug 29, 2024
- JupyterLab: XSS via untrusted notebook contentHighAug 28, 2024
llama.cpp (RPC backend): Unsafe `data` pointer in `rpc_tensor`CriticalAug 12, 2024
llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`MediumAug 12, 2024- JupyterHub: A user granted limited access can escalateHighAug 8, 2024
- TorchServe: `allowed_urls` bypassCriticalJul 19, 2024
- TorchServe (gRPC 7070/7071): gRPC ports bound to all interfaces regardless of configHighJul 19, 2024
LocalAI (`/models/apply`): SSRF and partial local file inclusionMediumJul 6, 2024- Gradio: Code injection via `gradio/component_meta.py`CriticalJul 1, 2024
- langchain-experimental (Python REPL): Python REPL exposed without an opt-inHighJun 16, 2024
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCriticalJun 11, 2024
- PyTorch Lightning: RCE via deserialization of untrusted checkpointCriticalJun 6, 2024
- ONNX (`download_model_with_test_data`): Arbitrary file overwrite from a crafted model archiveHighJun 6, 2024
- Gradio (`/queue/join`): SSRFHighJun 6, 2024
LiteLLM: Arbitrary file deletion via `/audio/transcriptions`HighJun 6, 2024- LangChain (Web Research Retriever): SSRFHighJun 6, 2024
- Jupyter Server (Windows): Unauthenticated attackers can leak the NTLM hash of the hostHighJun 6, 2024
- MLflow (model flavors): Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)HighJun 4, 2024
- MLflow (recipes / pyfunc): RCE via a maliciously crafted MLprojectHighJun 4, 2024
- Qdrant (snapshot recovery): Arbitrary file read and write during snapshot recoveryCriticalJun 3, 2024
- Ollama: Path traversal in the digest fieldHighMay 31, 2024
- joblib (`NumpyArrayWrapper.read_array`): Deserialization vulnerability in joblib 1.4.2HighMay 17, 2024
llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CriticalMay 14, 2024
llama.cpp (`gguf_init_from_file`): Use of uninitialized heap variableHighApr 26, 2024- PyTorch (flatbuffer loader): Out-of-bounds read parsing flatbuffer modelMediumApr 19, 2024
- PyTorch (mobile interpreter): Use-after-free in `torch/csrc/jit/mobile/interpreter.cpp`HighApr 17, 2024
- BentoML: Insecure deserializationCriticalApr 16, 2024
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCriticalApr 16, 2024
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCriticalApr 16, 2024
- MLflow (`_create_model_version`): Path traversal in model-version creationHighApr 16, 2024
- Gradio (`/component_server`): Arbitrary method invocation on componentsHighApr 16, 2024
- Qdrant (snapshot upload): Path traversal + arbitrary file upload via `/collections/{c}/snapshots/upload`CriticalApr 10, 2024
- Gradio: Local file inclusion via improper input validationHighApr 10, 2024
- Ollama: DNS rebinding grants a remote page full API accessMediumApr 8, 2024
- JupyterHub: Malicious subdomain tricks a userHighMar 27, 2024
- Gradio: SSRF in the `/proxy` routeMediumMar 27, 2024
- Jupyter Server Proxy: Authentication weakness in proxied-process accessCriticalMar 20, 2024
- LangChain: Directory traversal via the template path parameterHighMar 4, 2024
- langchain-experimental: Second bypass of CVE-2023-44467CriticalFeb 26, 2024
llama.cpp / GGUF library: Heap buffer overflow in GGUF `infoHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `GGUF_TYPE_ARRAY`/`GGUF_TYPE_STRING` parsingHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `header.n_tensors` handlingHighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `gguf_fread_str`HighFeb 26, 2024
llama.cpp / GGUF: Heap overflow in `header.n_kv`HighFeb 26, 2024- ONNX: Directory traversal in `external_data` — bypass of the 1.13 fixHighFeb 23, 2024
ClearML web server: XSSCriticalFeb 6, 2024
ClearML fileserver: No authentication — arbitrary read/write/delete of all stored artifactsCriticalFeb 6, 2024
ClearML API server: CSRF against the API serverCriticalFeb 6, 2024
ClearML client SDK: Deserialization of untrusted dataHighFeb 6, 2024
ClearML client SDK: Path traversal — a malicious dataset writes arbitrary files on the consumerHighFeb 6, 2024- Gradio: Remotely triggerable local file include via a JSON value in an API requestCriticalFeb 5, 2024
ClearML: Passwords stored in plaintext in MongoDBMediumFeb 5, 2024- jupyter-lsp: Unauthenticated file read/write through the LSP extensionHighJan 18, 2024
- Pure Storage FlashArray Purity API endpoint: A specific call to a FlashArray endpoint escalates the caller's privilegesCritical2024
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryHigh2024
20212
20203
- TensorFlow (SavedModel protobuf): Mutating a SavedModel protobuf crashes or corrupts the serving processCriticalSep 25, 2020
- TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer modelsMediumSep 25, 2020
- scikit-learn / joblib: `joblib.load()` executes commands from an untrusted file via `__reduce__`CriticalMay 15, 2020