Database/AI/ML frameworks & serving
LangChain (recursive URL loader): SSRF — crawling proceeds to internal hosts
CVSS 8.8CVE-2023-46229AI/ML frameworks & servingcurated
Impact
SSRF — crawling proceeds to internal hosts
Who can reach it
Attacker-supplied or crawled external page
What to do
Upgrade past 0.0.317; egress-restrict RAG ingestion workers
References
Related entries
- llama.cpp / GGUF library: Heap buffer overflow in GGUF `infoCVE-2024-21802 · llama.cpp / GGUF libraryHigh
- llama.cpp / GGUF: Heap overflow in `GGUF_TYPE_ARRAY`/`GGUF_TYPE_STRING` parsingCVE-2024-21825 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `header.n_tensors` handlingCVE-2024-21836 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `gguf_fread_str`CVE-2024-23496 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `header.n_kv`CVE-2024-23605 · llama.cpp / GGUFHigh
- Ollama: Path traversal in the digest fieldCVE-2024-37032 · OllamaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.