Database/AI/ML frameworks & serving
TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer models
CVSS 4.8CVE-2020-15211AI/ML frameworks & servingcurated
Impact
Out-of-bounds via duplicate tensor indices in flatbuffer models
Who can reach it
Customer-supplied TFLite model
What to do
Patch; edge/CPU inference tiers only
References
Related entries
- Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalationCVE-2026-35502 · Intel Extension for PyTorch (untrusted deserialization)Medium
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`CVE-2026-65920 · diffusers (shard file loader)Medium
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryCVE-2026-71486 · vLLM OpenAI-compatible server (/v1/completions/derender and /v1/chat/completions/derender)Medium
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sCVE-2023-31306 · AMD graphics driver - dynamic power management (DPM) array index validationLow
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityCVE-2026-15605 · wandb SDK (`ArtifactManifestEntry.download`)Low
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesCVE-2025-25183 · vLLM (prefix cache hash collisions)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.